Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Network Registrar DHCP Denial of Service Vulnerability

cisco-sa-cpnr-dhcp-dos-BkEZfhLP · High · Published · Updated

A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of incoming DHCP traffic. An attacker could exploit this vulnerability by sending a crafted DHCP request to an affected device. A successful exploit could allow the attacker to cause a restart of the DHCP server process, causing a DoS condition. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cpnr-dhcp-dos-BkEZfhLP

Workarounds

There is a workaround available for customers who cannot upgrade to a fixed release. To coordinate implementation of the workaround, contact the Cisco Technical Assistance Center (TAC) https://www.cisco.com/go/tac/ .

CVEsCVE-2020-3272
Cisco Bug IDsCSCvs77733
CVSS ScoreBase 7.5
Base 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Prime Network Registrar

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Prime Network Registrar known_affected cisco_csaf CVE-2020-3272 1

Related Products

Product CVE Evidence
Cisco Prime Network CVE-2020-3272 Cisco OpenVuln
Cisco Prime Network Registrar CVE-2020-3272 Cisco OpenVuln