PT-2020-1657 · Cisco · Cisco Nx-Os+3
Published
2020-02-05
·
Updated
2023-04-20
·
CVE-2020-3120
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco FXOS Software (affected versions not specified)
Cisco IOS XR Software (affected versions not specified)
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the Cisco Discovery Protocol implementation could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol, and to exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Recommendations
For Cisco FXOS Software, update to a version that includes the fix for this vulnerability.
For Cisco IOS XR Software, update to a version that includes the fix for this vulnerability.
For Cisco NX-OS Software, update to a version that includes the fix for this vulnerability.
As a temporary workaround, consider restricting access to the Cisco Discovery Protocol to minimize the risk of exploitation.
Fix
DoS
Integer Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Fxos
Cisco Ios Xr
Cisco Nx-Os
Cisco Nexus