关键信息总结 漏洞概述 漏洞名称: Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability 严重性: High CVE编号: CVE-2020-3561 状态: Fixed 影响的产品 受影响的Cisco产品: - 1100 Integrated Services Routers - 4000 Series Integrated Services Routers - ASR 900 Series Aggregation Services Routers - ASR 1000 Series Aggregation Services Routers - Catalyst 1131I Dual-Band Access Points - Catalyst 1832I Gigabit Switches - Catalyst 2960X Series Edge Platforms - Catalyst 8500 Fabric Platforms - Catalyst 9300L Edge Platforms - Catalyst 9500 TrustSec Enabled Routers 确定设备配置 使用 命令检查是否启用了CAPWAP Inspector for NBAR。 已确认不受影响的产品 IOS Software IOS XR Software NX-OS Software 解决方案 Cisco建议客户升级到修复软件版本。 可以使用Cisco Software Checker工具确定设备是否受此漏洞影响。 利用和公开公告 Cisco Product Security Incident Response Team (PSIRT)未发现任何公开利用或缓解措施。 来源 此漏洞是在解决Cisco TAC支持案例期间发现的。 URL Cisco Security Advisory