CVE-2020-3527: Cisco Catalyst 9200 Series Switches Jumbo Frame Denial of Service Vulnerability
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of this device. A successful exploit could allow the attacker to crash the device fully before an automatic recovery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3527?
The severity of CVE-2020-3527 is high with a CVSS score of 8.6.
How does CVE-2020-3527 impact Cisco Catalyst 9200 Series Switches?
CVE-2020-3527 allows an unauthenticated, remote attacker to crash the device.
How can an attacker exploit CVE-2020-3527?
An attacker can exploit CVE-2020-3527 by sending jumbo frames or frames larger than the allowed size.
Which versions of Cisco IOS XE are affected by CVE-2020-3527?
Cisco IOS XE versions 16.9.0 to 16.9.5 and versions 16.12.0 to 16.12.3 are affected by CVE-2020-3527.
Where can I find more information about CVE-2020-3527?
More information about CVE-2020-3527 can be found on the Cisco Security Advisory website.