CVE-2020-3226: Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on received SIP messages. An attacker could exploit this vulnerability by sending crafted SIP messages to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3226?
The severity of CVE-2020-3226 is classified as high due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2020-3226?
To fix CVE-2020-3226, upgrade your Cisco IOS Software or Cisco IOS XE Software to a version that addresses the vulnerability.
Which versions of Cisco IOS are affected by CVE-2020-3226?
CVE-2020-3226 affects multiple versions of Cisco IOS, including versions 15.0(2)sg11a and 15.3(3) and later.
Can CVE-2020-3226 be exploited remotely?
Yes, CVE-2020-3226 can be exploited by an unauthenticated, remote attacker.
What impact does CVE-2020-3226 have on affected devices?
The impact of CVE-2020-3226 is a denial of service (DoS), which may cause devices to reload, affecting network availability.