PT-2020-1610 · Cisco · Cisco Ios Xr

Published

2020-02-05

·

Updated

2022-12-23

·

CVE-2020-3118

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software (affected versions not specified)
Description A vulnerability in the Cisco Discovery Protocol implementation could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The issue is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this by sending a malicious Cisco Discovery Protocol packet to an affected device, potentially causing a stack overflow and allowing the execution of arbitrary code with administrative privileges. This vulnerability can be exploited by an attacker in the same broadcast domain as the affected device, as Cisco Discovery Protocol is a Layer 2 protocol.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use of Externally-Controlled Format String

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2020-00788
CVE-2020-3118

Affected Products

Cisco Ios Xr