5.9

CVE-2020-3353

Cisco Identity Services Engine Denial of Service Vulnerability

A vulnerability in the syslog processing engine of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a race condition that may occur when syslog messages are processed. An attacker could exploit this vulnerability by sending a high rate of syslog messages to an affected device. A successful exploit could allow the attacker to cause the Application Server process to crash, resulting in a DoS condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update -
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch1
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch10
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch11
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch12
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch2
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch3
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch4
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch5
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch6
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch7
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch8
Cisco ≫ Identity Services Engine Version 2.2.0.470 Update patch9
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update -
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update patch1
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update patch2
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update patch3
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update patch4
Cisco ≫ Identity Services Engine Version 2.3.0.298 Update patch5
Cisco ≫ Identity Services Engine Version 2.4.0.357 Update -
Cisco ≫ Identity Services Engine Version 2.4.0.357 Update patch1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.76% 0.504
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Cisco PSIRT 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-qNzq39K7
Vendor Advisory