CVE-2020-3510: Cisco IOS XE Software for Catalyst 9200 Series Switches Umbrella Connector Denial of Service Vulnerability
A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vulnerability is due to insufficient error handling when parsing DNS requests. An attacker could exploit this vulnerability by sending a series of malicious DNS requests to an Umbrella Connector client interface of an affected device. A successful exploit could allow the attacker to cause a crash of the iosd process, which triggers a reload of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3510?
CVE-2020-3510 is a vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches that could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device.
What is the severity of CVE-2020-3510?
The severity of CVE-2020-3510 is rated as high with a CVSS score of 8.6.
What software versions are affected by CVE-2020-3510?
The affected software versions are Cisco IOS XE 16.12.1, 16.12.2, and 17.1.1.
How can an attacker exploit CVE-2020-3510?
An attacker can exploit CVE-2020-3510 by sending specially crafted network traffic to the vulnerable device.
Is there a fix for CVE-2020-3510?
Yes, Cisco has released software updates to address the vulnerability. Please refer to the Cisco security advisory for more information.