CVE Vulnerabilities

CVE-2020-3220

Insufficient Verification of Data Authenticity

Published: Jun 03, 2020 | Modified: Jun 10, 2020
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected device. The vulnerability is due to insufficient verification of authenticity of received Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by tampering with ESP cleartext values as a man-in-the-middle.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Ios_xe Cisco 16.4.1 (including) 16.4.1 (including)
Ios_xe Cisco 16.4.2 (including) 16.4.2 (including)
Ios_xe Cisco 16.4.3 (including) 16.4.3 (including)
Ios_xe Cisco 16.5.1 (including) 16.5.1 (including)
Ios_xe Cisco 16.5.1a (including) 16.5.1a (including)
Ios_xe Cisco 16.5.1b (including) 16.5.1b (including)
Ios_xe Cisco 16.5.2 (including) 16.5.2 (including)
Ios_xe Cisco 16.5.3 (including) 16.5.3 (including)
Ios_xe Cisco 16.6.1 (including) 16.6.1 (including)
Ios_xe Cisco 16.6.2 (including) 16.6.2 (including)
Ios_xe Cisco 16.6.3 (including) 16.6.3 (including)
Ios_xe Cisco 16.6.4 (including) 16.6.4 (including)
Ios_xe Cisco 16.6.4a (including) 16.6.4a (including)
Ios_xe Cisco 16.6.4s (including) 16.6.4s (including)
Ios_xe Cisco 16.6.5 (including) 16.6.5 (including)
Ios_xe Cisco 16.6.5a (including) 16.6.5a (including)
Ios_xe Cisco 16.6.5b (including) 16.6.5b (including)
Ios_xe Cisco 16.6.6 (including) 16.6.6 (including)
Ios_xe Cisco 16.7.1 (including) 16.7.1 (including)
Ios_xe Cisco 16.7.1a (including) 16.7.1a (including)
Ios_xe Cisco 16.7.1b (including) 16.7.1b (including)
Ios_xe Cisco 16.7.2 (including) 16.7.2 (including)
Ios_xe Cisco 16.7.3 (including) 16.7.3 (including)
Ios_xe Cisco 16.7.4 (including) 16.7.4 (including)
Ios_xe Cisco 16.8.1 (including) 16.8.1 (including)
Ios_xe Cisco 16.8.1a (including) 16.8.1a (including)
Ios_xe Cisco 16.8.1b (including) 16.8.1b (including)
Ios_xe Cisco 16.8.1c (including) 16.8.1c (including)
Ios_xe Cisco 16.8.1d (including) 16.8.1d (including)
Ios_xe Cisco 16.8.1e (including) 16.8.1e (including)
Ios_xe Cisco 16.8.1s (including) 16.8.1s (including)
Ios_xe Cisco 16.8.2 (including) 16.8.2 (including)
Ios_xe Cisco 16.8.3 (including) 16.8.3 (including)
Ios_xe Cisco 16.9.1 (including) 16.9.1 (including)
Ios_xe Cisco 16.9.1a (including) 16.9.1a (including)
Ios_xe Cisco 16.9.1b (including) 16.9.1b (including)
Ios_xe Cisco 16.9.1c (including) 16.9.1c (including)
Ios_xe Cisco 16.9.1d (including) 16.9.1d (including)
Ios_xe Cisco 16.9.1s (including) 16.9.1s (including)
Ios_xe Cisco 16.9.2 (including) 16.9.2 (including)
Ios_xe Cisco 16.9.2a (including) 16.9.2a (including)
Ios_xe Cisco 16.9.2s (including) 16.9.2s (including)
Ios_xe Cisco 16.9.3 (including) 16.9.3 (including)
Ios_xe Cisco 16.9.3a (including) 16.9.3a (including)
Ios_xe Cisco 16.9.3h (including) 16.9.3h (including)
Ios_xe Cisco 16.9.3s (including) 16.9.3s (including)
Ios_xe Cisco 16.10.1 (including) 16.10.1 (including)
Ios_xe Cisco 16.10.1a (including) 16.10.1a (including)
Ios_xe Cisco 16.10.1b (including) 16.10.1b (including)
Ios_xe Cisco 16.10.1c (including) 16.10.1c (including)
Ios_xe Cisco 16.10.1d (including) 16.10.1d (including)
Ios_xe Cisco 16.10.1e (including) 16.10.1e (including)
Ios_xe Cisco 16.10.1f (including) 16.10.1f (including)
Ios_xe Cisco 16.10.1g (including) 16.10.1g (including)
Ios_xe Cisco 16.10.1s (including) 16.10.1s (including)
Ios_xe Cisco 16.10.2 (including) 16.10.2 (including)
Ios_xe Cisco 16.11.1 (including) 16.11.1 (including)
Ios_xe Cisco 16.11.1a (including) 16.11.1a (including)
Ios_xe Cisco 16.11.1b (including) 16.11.1b (including)
Ios_xe Cisco 16.11.1c (including) 16.11.1c (including)
Ios_xe Cisco 16.11.1s (including) 16.11.1s (including)
Ios_xe Cisco 16.12.1 (including) 16.12.1 (including)
Ios_xe Cisco 16.12.1a (including) 16.12.1a (including)
Ios_xe Cisco 16.12.1c (including) 16.12.1c (including)
Ios_xe Cisco 16.12.1s (including) 16.12.1s (including)
Ios_xe Cisco 16.12.1t (including) 16.12.1t (including)
Ios_xe Cisco 16.12.1w (including) 16.12.1w (including)
Ios_xe Cisco 16.12.1y (including) 16.12.1y (including)

References