CVE-2020-3235 is a denial-of-service vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software on Catalyst 4500 Series Switches, also affecting Oracle products. It allows an authenticated, remote attacker to cause a device reload by sending a crafted SNMP packet due to insufficient input validation. With a CVSS score of 7.7 (HIGH), this vulnerability requires prior authentication (SNMP community string or user credentials) and has a low attack complexity, potentially leading to a complete service disruption. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(52\)sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(52\)sg:*:*:*:*:*:*:* | ||
12.2\(53\)sg1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(53\)sg1:*:*:*:*:*:*:* | ||
12.2\(53\)sg2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(53\)sg2:*:*:*:*:*:*:* | ||
12.2\(53\)sg3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(53\)sg3:*:*:*:*:*:*:* | ||
12.2\(53\)sg4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(53\)sg4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.