CVE-2020-3230: Cisco IOS and IOS XE Software Internet Key Exchange Version 2 Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations. The vulnerability is due to incorrect handling of crafted IKEv2 SA-Init packets. An attacker could exploit this vulnerability by sending crafted IKEv2 SA-Init packets to the affected device. An exploit could allow the attacker to cause the affected device to reach the maximum incoming negotiation limits and prevent further IKEv2 security associations from being formed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3230?
CVE-2020-3230 is categorized as a critical vulnerability due to its potential impact on security association establishment.
How do I fix CVE-2020-3230?
To remediate CVE-2020-3230, update your Cisco IOS or Cisco IOS XE software to the recommended versions provided in the official advisory.
What systems are affected by CVE-2020-3230?
CVE-2020-3230 affects multiple versions of Cisco IOS and Cisco IOS XE, specifically from 12.2(6)i1 through various 15.x versions.
Can CVE-2020-3230 be exploited remotely?
Yes, CVE-2020-3230 can be exploited by unauthenticated remote attackers to disrupt IKEv2 connections.
What type of vulnerability is CVE-2020-3230?
CVE-2020-3230 is an implementation vulnerability in the Internet Key Exchange Version 2 (IKEv2) protocol.