CVE-2023-20080: Cisco IOS and IOS XE Software IPv6 DHCP (DHCPv6) Relay and Server Denial of Service Vulnerability
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 messages to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20080?
CVE-2023-20080 has a medium severity level, potentially leading to a denial of service (DoS) condition.
How does CVE-2023-20080 impact systems?
CVE-2023-20080 can allow unauthenticated attackers to exploit insufficient validation in the DHCPv6 relay and server features, causing DoS.
How do I fix CVE-2023-20080?
To fix CVE-2023-20080, apply the latest patches provided by Cisco for the affected IOS and IOS XE software versions.
Which Cisco products are affected by CVE-2023-20080?
CVE-2023-20080 affects multiple versions of Cisco IOS and IOS XE software, including specific releases such as 12.2(6)i1 and 15.1(2)sg.
What are the potential risks of CVE-2023-20080?
The risks associated with CVE-2023-20080 include potential disruptions to network services and loss of availability due to an attacker causing a DoS condition.