CVE-2020-3508: Cisco IOS XE
High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition. The vulnerability is due to insufficient error handling when an affected device has reached platform limitations. An attacker could exploit this vulnerability by sending a malicious series of IP ARP messages to an affected device. A successful exploit could allow the attacker to exhaust system resources, which would eventually cause the affected device to reload.
Affected products
- Cisco IOS XE: version 16.3.1 only; version 16.6.5 only; version 16.7(1) only; version 17.1.1 only; version 16.9.1 only; version 17.4.1 only
Published 2020-09-24. Last modified 2026-06-17.