A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition. The vulnerability is due to insufficient error handling when an affected device has reached platform limitations. An attacker could exploit this vulnerability by sending a malicious series of IP ARP messages to an affected device. A successful exploit could allow the attacker to exhaust system resources, which would eventually cause the affected device to reload.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esp20-arp-dos-GvHVggqJ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2020-09-24 18:15
Updated : 2024-02-28 18:08
NVD link : CVE-2020-3508
Mitre link : CVE-2020-3508
CVE.ORG link : CVE-2020-3508
JSON object : View
Products Affected
cisco
- 4321\/k9-ws_integrated_services_router
- catalyst_3850-16xs-e
- catalyst_3650-8x24pd-e
- 4321\/k9_integrated_services_router
- catalyst_3650-12x48fd-l
- catalyst_3650-48fqm-s
- 1109-2p_integrated_services_router
- catalyst_3650-48ts-l
- catalyst_3850-32xs-s
- 1100-lte_integrated_services_router
- 4351\/k9-rf_integrated_services_router
- 1000v
- catalyst_3650-48tq-s
- 4431_integrated_services_router
- asr_1002-hx
- catalyst_3650-24pd-e
- 4321_integrated_services_router
- catalyst_3850-24p-s
- catalyst_3850-24xu-e
- 1100-4g_integrated_services_router
- catalyst_3850-24xs-s
- catalyst_3650-8x24pd-s
- catalyst_3650-24pd-s
- catalyst_3650-48td-s
- catalyst_3850-48xs-f-e
- catalyst_3650-48pd-e
- catalyst_3650-24td-e
- 1160_integrated_services_router
- catalyst_3650-12x48fd-e
- catalyst_3850-48u-e
- catalyst_3650-48fq-e
- catalyst_3650-48fd-s
- catalyst_3850-24u-l
- asr_1023
- catalyst_3650-24ps-l
- 1100-4p_integrated_services_router
- catalyst_3650-48tq-e
- catalyst_3650-48ts-s
- 4331\/k9-rf_integrated_services_router
- catalyst_3650-48pq-e
- catalyst_3650-48pd-s
- catalyst_3850-48f-s
- 111x_integrated_services_router
- catalyst_3650-48ps-l
- catalyst_3850-24xu-s
- catalyst_3650-48fs-e
- catalyst_3650-24ts-e
- catalyst_3650-48td-e
- catalyst_3850-48p-l
- catalyst_c3850-12x48u-l
- 1120_integrated_services_router
- 1109_integrated_services_router
- 4321\/k9-rf_integrated_services_router
- asr_1001
- catalyst_3850-24u-s
- catalyst_3850-24t-l
- 1111x_integrated_services_router
- asr_1002-x
- catalyst_3650-24td-s
- catalyst_3850-24p-l
- catalyst_3850-12s-e
- catalyst_3850-12xs-s
- asr_1001-x
- catalyst_3650-12x48fd-s
- catalyst_3650-48fd-l
- catalyst_3650-48tq-l
- catalyst_3850-24xu-l
- 4331\/k9-ws_integrated_services_router
- catalyst_c3850-12x48u-e
- catalyst_3650-48fs-s
- 4351_integrated_services_router
- asr_1001-hx
- catalyst_3850-24p-e
- catalyst_3650-48pq-l
- 1100-4gltegb_integrated_services_router
- 1100-6g_integrated_services_router
- 4331_integrated_services_router
- catalyst_3850-24xs-e
- catalyst_3850-24u-e
- catalyst_c3850-12x48u-s
- catalyst_3650-48td-l
- 4351\/k9_integrated_services_router
- asr_1006
- catalyst_3650-24td-l
- 4461_integrated_services_router
- 4351\/k9-ws_integrated_services_router
- catalyst_3650-48ts-e
- catalyst_3850-48p-s
- catalyst_3650-48fs-l
- catalyst_3850-48xs-e
- catalyst_3650-24pdm-s
- catalyst_3850-48p-e
- asr_1004
- 1101-4p_integrated_services_router
- catalyst_3650-48pd-l
- catalyst_3850-12s-s
- asr_1002
- catalyst_3850-48xs-s
- catalyst_3650-48ps-s
- csr1000v
- catalyst_3850-48u-s
- catalyst_3850-48u-l
- catalyst_3650-24ts-s
- asr_1000
- 1101_integrated_services_router
- catalyst_3650-48fd-e
- catalyst_3850-48t-l
- catalyst_3850-48f-e
- catalyst_3650-24pdm-l
- catalyst_3850-48xs-f-s
- asr_1000-x
- catalyst_3850-12xs-e
- catalyst_3650-24pd-l
- ios_xe
- catalyst_3650-48fq-l
- catalyst_3850-24t-e
- catalyst_3650-48fqm-l
- 1100-8p_integrated_services_router
- 1111x-8p_integrated_services_router
- catalyst_3650-24pdm-e
- catalyst_3650-8x24pd-l
- catalyst_3650-48ps-e
- catalyst_3850-16xs-s
- catalyst_3850-24s-e
- catalyst_3650-48fqm-e
- catalyst_3850-48t-s
- catalyst_3850-48f-l
- 1109-4p_integrated_services_router
- catalyst_3650-48pq-s
- 4331\/k9_integrated_services_router
- catalyst_3650-48fq-s
- catalyst_3650-24ts-l
- asr_1013
- catalyst_3850-32xs-e
- 1100_integrated_services_router
- catalyst_3850-48t-e
- 1100-4gltena_integrated_services_router
- catalyst_3850-24s-s
- catalyst_3650-24ps-e
- catalyst_3850-24t-s
- catalyst_3650-24ps-s
CWE
CWE-400
Uncontrolled Resource Consumption