CVE-2020-3526: Cisco IOS XE Software Common Open Policy Service Engine Denial of Service Vulnerability
A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a malformed COPS message to the device. A successful exploit could allow the attacker to crash the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3526?
CVE-2020-3526 is a vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers.
What is the severity of CVE-2020-3526?
The severity of CVE-2020-3526 is high with a CVSS score of 8.6.
How can an attacker exploit CVE-2020-3526?
An attacker could exploit CVE-2020-3526 by sending malicious requests to the Common Open Policy Service (COPS) engine, causing a device crash.
Which software versions are affected by CVE-2020-3526?
Cisco IOS XE Software version 17.2 on Cisco cBR-8 Converged Broadband Routers is affected by CVE-2020-3526.
Is Cisco cBR-8 vulnerable to CVE-2020-3526?
No, Cisco cBR-8 is not vulnerable to CVE-2020-3526.