A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected device. The vulnerability is due to insufficient verification of authenticity of received Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by tampering with ESP cleartext values as a man-in-the-middle.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2020-06-03T17:41:40.234773Z

Updated: 2024-09-16T16:14:18.978Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2020-3220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-06-03T18:15:19.997

Modified: 2020-06-10T23:45:32.260

Link: CVE-2020-3220

cve-icon Redhat

No data.