PT-2020-1994 · Cisco · Cisco Nx-Os+1
Published
2020-02-26
·
Updated
2020-03-04
·
CVE-2020-3165
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability occurs because the BGP MD5 authentication is bypassed if the peer does not have MD5 authentication configured, the NX-OS device does have BGP MD5 authentication configured, and the NX-OS BGP virtual routing and forwarding (VRF) name is configured to be greater than 19 characters. An attacker could exploit this vulnerability by attempting to establish a BGP session with the NX-OS peer. A successful exploit could allow the attacker to establish a BGP session with the NX-OS device without MD5 authentication. The Cisco implementation of the BGP protocol accepts incoming BGP traffic only from explicitly configured peers. To exploit this vulnerability, an attacker must send the malicious packets over a TCP connection that appears to come from a trusted BGP peer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
However, Cisco has released software updates that address this vulnerability, and there are workarounds that address this vulnerability.
As a temporary workaround, consider restricting access to the BGP protocol to minimize the risk of exploitation.
Restrict access to the
VRF name to prevent it from being configured to be greater than 19 characters.
Avoid using the BGP MD5 authentication with peers that do not have MD5 authentication configured.Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus