PT-2020-1657 · Cisco · Cisco Nx-Os+3

CVE-2020-3120

·

Published

2020-02-05

·

Updated

2023-04-20

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software (affected versions not specified) Cisco IOS XR Software (affected versions not specified) Cisco NX-OS Software (affected versions not specified)
Description A vulnerability in the Cisco Discovery Protocol implementation could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol, and to exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Recommendations For Cisco FXOS Software, update to a version that includes the fix for this vulnerability. For Cisco IOS XR Software, update to a version that includes the fix for this vulnerability. For Cisco NX-OS Software, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the Cisco Discovery Protocol to minimize the risk of exploitation.

Fix

DoS

Integer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00890
CVE-2020-3120

Affected Products

Cisco Fxos
Cisco Ios Xr
Cisco Nx-Os
Cisco Nexus