MEDIUM · 5.3

CVE-2020-3496

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on ...

Vulnerability Description

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the switch management CLI to stop responding, resulting in a DoS condition. This vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
CiscoSg200-50 Firmware<= 2.5.5.47
CiscoSg200-50-
CiscoSg200-50P Firmware<= 2.5.5.47
CiscoSg200-50P-
CiscoSg200-50Fp Firmware<= 2.5.5.47
CiscoSg200-50Fp-
CiscoSg200-26 Firmware<= 2.5.5.47
CiscoSg200-26-
CiscoSg200-26P Firmware<= 2.5.5.47
CiscoSg200-26P-
CiscoSg200-26Fp Firmware<= 2.5.5.47
CiscoSg200-26Fp-
CiscoSg200-18 Firmware<= 2.5.5.47
CiscoSg200-18-
CiscoSg200-10Fp Firmware<= 2.5.5.47
CiscoSg200-10Fp-
CiscoSg200-08 Firmware<= 2.5.5.47
CiscoSg200-08-
CiscoSg200-08P Firmware<= 2.5.5.47
CiscoSg200-08P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-3496?

CVE-2020-3496 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on ...

How severe is CVE-2020-3496?

CVE-2020-3496 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-3496?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Sg200-50 Firmware, Cisco Sg200-50, Cisco Sg200-50P Firmware, Cisco Sg200-50P, Cisco Sg200-50Fp Firmware.