CVE-2020-3200: Cisco IOS and IOS XE Software Secure Shell Denial of Service Vulnerability
A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. The vulnerability is due to an internal state not being represented correctly in the SSH state machine, which leads to an unexpected behavior. An attacker could exploit this vulnerability by creating an SSH connection to an affected device and using a specific traffic pattern that causes an error condition within that connection. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3200?
CVE-2020-3200 has a CVSS base score of 7.5, indicating a high severity level.
How do I fix CVE-2020-3200?
To mitigate CVE-2020-3200, users should update their Cisco IOS and IOS XE Software to the versions recommended in the Cisco security advisory.
What type of vulnerability is CVE-2020-3200?
CVE-2020-3200 is a denial of service vulnerability that affects the SSH server code of specific Cisco software.
Who is affected by CVE-2020-3200?
CVE-2020-3200 impacts users of Cisco IOS Software and Cisco IOS XE Software on devices running certain versions.
What conditions are required for CVE-2020-3200 to be exploited?
An attacker must have valid authentication credentials and be able to connect to the affected device via SSH to exploit CVE-2020-3200.