PT-2020-3780 · Cisco · Cisco Nx-Os+2

Published

2020-08-26

·

Updated

2023-04-20

·

CVE-2020-3517

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco FXOS Software and Cisco NX-OS Software (affected versions not specified)
Description: A vulnerability in the Cisco Fabric Services component could allow an unauthenticated attacker to cause process crashes, resulting in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. The vulnerability is due to insufficient error handling when the affected software parses Cisco Fabric Services messages. An attacker could exploit this vulnerability by sending malicious Cisco Fabric Services messages to an affected device, potentially causing a reload of the device and resulting in a DoS condition.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04140
CVE-2020-3517

Affected Products

Cisco Fxos
Cisco Nx-Os
Cisco Nexus