7.4

CVE-2020-3511

A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the ISDN Q.931 messages are processed. An attacker could exploit this vulnerability by sending a malicious ISDN Q.931 message to an affected device. A successful exploit could allow the attacker to cause the process to crash, resulting in a reload of the affected device.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version15.1(4)m
   Cisco1100-4g Integrated Services Router Version-
   Cisco1100-4gltegb Integrated Services Router Version-
   Cisco1100-4gltena Integrated Services Router Version-
   Cisco1100-4p Integrated Services Router Version-
   Cisco1100-6g Integrated Services Router Version-
   Cisco1100-8p Integrated Services Router Version-
   Cisco1100-lte Integrated Services Router Version-
   Cisco1100 Integrated Services Router Version-
   Cisco1101-4p Integrated Services Router Version-
   Cisco1101 Integrated Services Router Version-
   Cisco1109-2p Integrated Services Router Version-
   Cisco1109-4p Integrated Services Router Version-
   Cisco1109 Integrated Services Router Version-
   Cisco1111x-8p Integrated Services Router Version-
   Cisco1111x Integrated Services Router Version-
   Cisco111x Integrated Services Router Version-
   Cisco1120 Integrated Services Router Version-
   Cisco1160 Integrated Services Router Version-
   Cisco422 Integrated Services Router Version-
   Cisco4321/k9-rf Integrated Services Router Version-
   Cisco4321/k9-ws Integrated Services Router Version-
   Cisco4321/k9 Integrated Services Router Version-
   Cisco4331/k9-rf Integrated Services Router Version-
   Cisco4331/k9-ws Integrated Services Router Version-
   Cisco4331/k9 Integrated Services Router Version-
   Cisco4351/k9-rf Integrated Services Router Version-
   Cisco4351/k9-ws Integrated Services Router Version-
   Cisco4351/k9 Integrated Services Router Version-
   Cisco4431 Integrated Services Router Version-
   Cisco4461 Integrated Services Router Version-
   CiscoAsr 1000-x Version-
   CiscoAsr 1001 Version-
   CiscoAsr 1001-x Version-
   CiscoAsr 1002 Version-
   CiscoAsr 1002-x Version-
   CiscoAsr 1004 Version-
   CiscoAsr 1006 Version-
   CiscoAsr 1013 Version-
   CiscoAsr1001-hx Version-
   CiscoAsr1001-hx-rf Version-
   CiscoAsr1001-x Version-
   CiscoAsr1001-x-rf Version-
   CiscoAsr1001-x-ws Version-
   CiscoAsr1002-hx Version-
   CiscoAsr1002-hx-rf Version-
   CiscoAsr1002-hx-ws Version-
   CiscoAsr1002-x Version-
   CiscoAsr1002-x-rf Version-
   CiscoAsr1002-x-ws Version-
   CiscoCsr1000v Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.249
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:N/I:N/A:C
psirt@cisco.com 7.4 2.8 4
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.