A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected device. The vulnerability is due to insufficient verification of authenticity of received Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by tampering with ESP cleartext values as a man-in-the-middle.
History

Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2020-06-03T17:41:40.234773Z

Updated: 2024-11-15T17:16:04.512Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2020-3220

cve-icon Vulnrichment

Updated: 2024-08-04T07:30:56.480Z

cve-icon NVD

Status : Modified

Published: 2020-06-03T18:15:19.997

Modified: 2024-11-21T05:30:35.417

Link: CVE-2020-3220

cve-icon Redhat

No data.