CVE-2020-3409 describes a denial-of-service vulnerability in the PROFINET feature of Cisco IOS and IOS XE Software. An unauthenticated, adjacent attacker can exploit this by sending specially crafted PROFINET packets, causing the affected device to crash and reload. With a CVSS score of 7.4 (High), this vulnerability has a low attack complexity and requires no user interaction, but only affects devices on the same network segment. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, and it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(7\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(7\)e:*:*:*:*:*:*:* | ||
15.2\(7\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.2\(7\)e:*:*:*:*:*:*:* | ||
16.11.1aCPE matchmatch criteria | cpe:2.3:a:cisco:ios_xe:16.11.1a:*:*:*:*:*:*:* | ||
16.11.1aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:16.11.1a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.