PT-2020-1610 · Cisco · Cisco Ios Xr
Published
2020-02-05
·
Updated
2022-12-23
·
CVE-2020-3118
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR Software (affected versions not specified)
Description
A vulnerability in the Cisco Discovery Protocol implementation could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The issue is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this by sending a malicious Cisco Discovery Protocol packet to an affected device, potentially causing a stack overflow and allowing the execution of arbitrary code with administrative privileges. This vulnerability can be exploited by an attacker in the same broadcast domain as the affected device, as Cisco Discovery Protocol is a Layer 2 protocol.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Use of Externally-Controlled Format String
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xr