CVE-2020-3407: Cisco IOS XE Software RESTCONF and NETCONF-YANG Access Control List Denial of Service Vulnerability
A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL that is tied to the RESTCONF or NETCONF-YANG feature. An attacker could exploit this vulnerability by accessing the device using RESTCONF or NETCONF-YANG. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3407?
CVE-2020-3407 has a severity rating of high due to its potential impact on device availability.
How do I fix CVE-2020-3407?
To mitigate CVE-2020-3407, update your Cisco IOS XE software to a fixed version as recommended by Cisco.
What Cisco devices are affected by CVE-2020-3407?
CVE-2020-3407 affects multiple versions of Cisco IOS XE software, specifically 15.8(3)m3.
What type of attack could exploit CVE-2020-3407?
An unauthenticated remote attacker could exploit CVE-2020-3407 to cause the affected device to reload.
Is there a workaround for CVE-2020-3407 until I can update?
Currently, there are no published workarounds for CVE-2020-3407; updating to a fixed version is recommended.