PT-2020-3780 · Cisco · Cisco Nx-Os+2
Published
2020-08-26
·
Updated
2023-04-20
·
CVE-2020-3517
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco FXOS Software and Cisco NX-OS Software (affected versions not specified)
Description:
A vulnerability in the Cisco Fabric Services component could allow an unauthenticated attacker to cause process crashes, resulting in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. The vulnerability is due to insufficient error handling when the affected software parses Cisco Fabric Services messages. An attacker could exploit this vulnerability by sending malicious Cisco Fabric Services messages to an affected device, potentially causing a reload of the device and resulting in a DoS condition.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Fxos
Cisco Nx-Os
Cisco Nexus