Files
CVEs-PoC/2020/CVE-2020-3221.md
T
2024-05-25 21:48:12 +02:00

18 lines
1.2 KiB
Markdown

### [CVE-2020-3221](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3221)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20IOS%20XE%20Software%2016.10.1&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-20&color=brighgreen)
### Description
A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of parameters in a Flexible NetFlow Version 9 record. An attacker could exploit this vulnerability by sending a malformed Flexible NetFlow Version 9 packet to the Control and Provisioning of Wireless Access Points (CAPWAP) data port of an affected device. An exploit could allow the attacker to trigger an infinite loop, resulting in a process crash that would cause a reload of the device.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/p1ay8y3ar/cve_monitor