CVE-2020-3235A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object identifiers. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: To exploit this vulnerability by using SNMPv2c or earlier, the attacker must know the SNMP read-only community string for an affected system. To exploit this vulnerability by using SNMPv3, the attacker must know the user credentials for the affected system.
CWE-118CWE-20 · Improper input validation
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 6 years.
CVSS E:U
In RASP's scope, but nothing published names a fix and nothing published shows an exploit. Neither of the two things VRT can act on exists, which is a claim about the available evidence, not about the vulnerability.
| Decided by | no-exploit : With no fix path, a public exploit, or a CISA record of one |
|---|---|
| Finding | Resolved from QUEUED-FOR-REVIEW: this CVE affects a known product, but nothing published names a fix and nothing published shows an exploit. That is a statement about the evidence, not about the defect — it does not mean the vulnerability is unimportant or unreachable, only that neither of the two things VRT can act on exists. |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
NVD | Primary | published |
| CVSS 3.0 | 7.7 | HIGH | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
psirt@cisco.com | Secondary | |
| CVSS 2.0 | 6.3 | no band published | AV:N/AC:M/Au:S/C:N/I:N/A:C |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update October 2020 ↗ | CPU | 2020-Q4 | Oracle Fusion Middleware / Monitor (SNMP) (12.2.1.2.0) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Fusion Middleware | Monitor (SNMP) | 12.2.1.2.0 | 12.2.1.2.0 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | cisco | ios | generic | 12.2\(52\)sg · 12.2\(53\)sg1 · 12.2\(53\)sg2 · 12.2\(53\)sg3 · 12.2\(53\)sg4 · 12.2\(53\)sg5 · 12.2\(53\)sg6 · 12.2\(53\)sg7 · 12.2\(53\)sg8 · 12.2\(53\)sg9 · 12.2\(53\)sg10 · 12.2\(53\)sg11 · 12.2\(54\)sg · 12.2\(54\)wo · 12.2\(54\)sg1 · 15.0\(1\)ey · 15.0\(1\)xo · 15.0\(1\)xo1 · 15.0\(1\)ey2 · 15.0\(2\)sg · 15.0\(2\)xo · 15.0\(2\)sg1 · 15.0\(2\)ex2 · 15.0\(2\)sg2 · 15.0\(2\)sg3 · 15.0\(2\)sg4 · 15.0\(2\)sg5 · 15.0\(2\)sg6 · 15.0\(2\)sg7 · 15.0\(2\)ex8 · 15.0\(2\)sg8 · 15.0\(2\)sg9 · 15.0\(2\)sg10 · 15.0\(2\)sg11 · 15.1\(1\)sg · 15.1\(1\)sg1 · 15.1\(1\)sg2 · 15.1\(2\)sg · 15.1\(2\)sg1 · 15.1\(2\)sg2 · 15.1\(2\)sg3 · 15.1\(2\)sg4 · 15.1\(2\)sg5 · 15.1\(2\)sg6 · 15.1\(2\)sg7 · 15.1\(2\)sg8 · 15.2\(1\)e · 15.2\(1\)e1 · 15.2\(1\)e3 · 15.2\(2\)e · 15.2\(2b\)e · 15.2\(2\)e1 · 15.2\(2\)e2 · 15.2\(2\)e3 · 15.2\(2\)e4 · 15.2\(2\)e5 · 15.2\(2\)e5a · 15.2\(2\)e5b · 15.2\(2\)e6 · 15.2\(2\)e7 · 15.2\(2\)e7b · 15.2\(2\)e8 · 15.2\(2\)e9 · 15.2\(2\)e9a · 15.2\(2\)e10 · 15.2\(3\)e · 15.2\(3\)e1 · 15.2\(3\)e2 · 15.2\(3\)e3 · 15.2\(3\)e4 · 15.2\(3\)e5 · 15.2\(4\)e · 15.2\(4\)e1 · 15.2\(4\)e2 · 15.2\(4\)e3 · 15.2\(4\)e4 · 15.2\(4\)e5 · 15.2\(4\)e5a · 15.2\(4\)e6 · 15.2\(4\)e7 · 15.2\(4\)e8 · 15.3\(3\)jpj |
| nvd | cisco | ios xe | generic | 3.2.0sg · 3.2.1sg · 3.2.2sg · 3.2.3sg · 3.2.4sg · 3.2.5sg · 3.2.6sg · 3.2.7sg · 3.2.8sg · 3.2.9sg · 3.2.10sg · 3.2.11sg · 3.3.0sg · 3.3.0xo · 3.3.1sg · 3.3.1xo · 3.3.2sg · 3.3.2xo · 3.4.0sg · 3.4.1sg · 3.4.2sg · 3.4.3sg · 3.4.4sg · 3.4.5sg · 3.4.6sg · 3.4.7sg · 3.4.8sg · 3.5.0e · 3.5.1e · 3.5.2e · 3.5.3e · 3.6.0be · 3.6.0e · 3.6.1e · 3.6.3e · 3.6.4e · 3.6.5ae · 3.6.5be · 3.6.5e · 3.6.6e · 3.6.7e · 3.6.8e · 3.6.9e · 3.6.10e · 3.7.0e · 3.7.1e · 3.7.2e · 3.7.3e · 3.8.0e · 3.8.1e · 3.8.2e · 3.8.3e · 3.8.4e · 3.8.5ae · 3.8.5e · 3.8.6e · 3.8.7e · 3.8.8e · 3.9.0e · 3.9.1e · 3.9.2be · 3.9.2e · 3.10.0ce · 3.10.0e · 3.10.1ae · 3.10.1e · 3.10.1se · 3.10.2e |
| nvd | oracle | goldengate management pack | generic | 12.2.1.2.0 |
| URL | Tags |
|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-USxSyTk5 | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Patch, Third Party Advisory |
| Published | 2020-06-03 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |