CVE-2020-3408: Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability
A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability occurs because the regular expression (regex) engine that is used with the Split DNS feature of affected releases may time out when it processes the DNS name list configuration. An attacker could exploit this vulnerability by trying to resolve an address or hostname that the affected device handles. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3408?
CVE-2020-3408 has been classified as a high-severity vulnerability because it can lead to a denial of service (DoS) condition.
How do I fix CVE-2020-3408?
To mitigate CVE-2020-3408, update affected Cisco IOS and IOS XE software to the latest fixed version.
Which Cisco products are affected by CVE-2020-3408?
CVE-2020-3408 affects Cisco IOS Software and Cisco IOS XE Software version 15.8(3)m3.
What type of vulnerability is CVE-2020-3408?
CVE-2020-3408 is a denial of service (DoS) vulnerability related to the Split DNS feature.
Can CVE-2020-3408 be exploited remotely?
Yes, CVE-2020-3408 can be exploited by an unauthenticated remote attacker.