CVE-2020-3235: Cisco IOS and IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object identifiers. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: To exploit this vulnerability by using SNMPv2c or earlier, the attacker must know the SNMP read-only community string for an affected system. To exploit this vulnerability by using SNMPv3, the attacker must know the user credentials for the affected system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3235?
CVE-2020-3235 is classified as a high severity vulnerability allowing denial of service due to SNMP issues in Cisco products.
How do I fix CVE-2020-3235?
To mitigate CVE-2020-3235, upgrade to the patched versions of Cisco IOS or Cisco IOS XE that address this vulnerability.
What systems are affected by CVE-2020-3235?
CVE-2020-3235 affects various versions of Cisco IOS and Cisco IOS XE on Catalyst 4500 Series switches.
Can CVE-2020-3235 be exploited remotely?
Yes, CVE-2020-3235 can be exploited by an authenticated remote attacker to cause a denial of service.
What impact does CVE-2020-3235 have on device functionality?
The exploitation of CVE-2020-3235 can lead to a denial of service condition, affecting network availability.