A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition. The vulnerability is due to insufficient error handling when an affected device has reached platform limitations. An attacker could exploit this vulnerability by sending a malicious series of IP ARP messages to an affected device. A successful exploit could allow the attacker to exhaust system resources, which would eventually cause the affected device to reload.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esp20-arp-dos-GvHVggqJ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2020-09-24 11:15
Updated : 2020-10-16 06:31
NVD link : CVE-2020-3508
Mitre link : CVE-2020-3508
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
cisco
- catalyst_3850-24u-e
- isr_4431
- asr_1001-hx
- catalyst_3850-24s-s
- catalyst_3650-48ps-l
- catalyst_3850-48p-s
- isr4321\/k9-ws
- 1000v
- isr4331\/k9-rf
- catalyst_3650-48fd-l
- catalyst_3650-48tq-e
- catalyst_3650-48fq-s
- isr_1111x-8p
- isr_1100-8p
- catalyst_3650-48td-l
- isr1100-6g
- isr4351\/k9-ws
- catalyst_3850-12xs-s
- asr_1006
- catalyst_c3850-12x48u-l
- catalyst_3850-24s-e
- asr_1001
- asr_1000-x
- catalyst_3850-12xs-e
- isr_4321
- isr_1100-4p
- catalyst_3650-48fs-s
- catalyst_3650-12x48fd-s
- catalyst_3650-48pd-s
- isr4331\/k9
- catalyst_3650-48fqm-e
- isr_1101
- catalyst_3850-24p-s
- catalyst_3650-8x24pd-e
- catalyst_3650-48tq-l
- isr1100-4gltegb
- isr1100-4gltena
- catalyst_3650-24ps-e
- isr4331\/k9-ws
- catalyst_3850-24t-e
- catalyst_3650-48fs-l
- catalyst_3850-48p-e
- catalyst_3650-24td-l
- catalyst_3650-48pq-e
- catalyst_3650-48fq-e
- catalyst_3650-24pdm-s
- catalyst_3650-24ts-s
- catalyst_3650-24pd-l
- catalyst_3850-24t-s
- catalyst_3850-24t-l
- isr_1109-4p
- catalyst_3850-24u-s
- csr1000v
- isr_111x
- asr_1002-x
- catalyst_3650-48ts-l
- catalyst_3650-48ps-s
- catalyst_3650-24pdm-l
- catalyst_3850-24xu-s
- catalyst_3850-24xu-e
- isr_4351
- catalyst_3650-24td-s
- catalyst_3650-48fq-l
- catalyst_3650-48ts-s
- catalyst_3850-48u-e
- catalyst_3850-48xs-e
- catalyst_3650-24ts-e
- catalyst_3850-32xs-e
- catalyst_3650-24pd-s
- asr_1013
- catalyst_3650-48fs-e
- catalyst_3850-12s-e
- catalyst_3850-48p-l
- catalyst_3850-48xs-f-s
- catalyst_3850-32xs-s
- isr1100
- catalyst_3650-24td-e
- catalyst_3650-48td-s
- isr_1101-4p
- catalyst_3650-48fqm-s
- catalyst_3850-48t-e
- catalyst_c3850-12x48u-e
- asr_1000
- catalyst_3850-48u-l
- catalyst_3850-24p-l
- catalyst_3650-48ts-e
- catalyst_3650-48fqm-l
- asr_1023
- asr_1002-hx
- catalyst_3650-48fd-e
- isr1100-4g
- isr_1109
- isr4321\/k9
- isr_1111x
- isr1100-lte
- catalyst_3650-48ps-e
- catalyst_3850-24xu-l
- isr_4461
- catalyst_3850-48t-s
- catalyst_3650-48td-e
- catalyst_3650-12x48fd-e
- catalyst_3850-48xs-s
- catalyst_3850-48f-s
- catalyst_3850-48f-e
- isr_1109-2p
- catalyst_3850-48xs-f-e
- catalyst_3650-8x24pd-s
- catalyst_3850-48t-l
- catalyst_3650-48tq-s
- catalyst_3650-48pq-l
- asr_1002
- isr4321\/k9-rf
- ios_xe
- catalyst_3650-24ps-s
- catalyst_3850-24p-e
- isr4351\/k9-rf
- catalyst_3650-24ts-l
- catalyst_3850-12s-s
- catalyst_3650-12x48fd-l
- catalyst_3650-48fd-s
- catalyst_3850-16xs-e
- catalyst_3850-24xs-s
- catalyst_3850-48u-s
- catalyst_3650-24pd-e
- catalyst_3650-48pd-l
- catalyst_3650-24ps-l
- catalyst_3850-24xs-e
- isr_1120
- isr_4331
- catalyst_3850-16xs-s
- catalyst_3650-48pq-s
- isr_1160
- isr4351\/k9
- catalyst_3650-8x24pd-l
- catalyst_3650-48pd-e
- catalyst_c3850-12x48u-s
- catalyst_3850-48f-l
- catalyst_3850-24u-l
- catalyst_3650-24pdm-e
- asr_1001-x
- asr_1004