Multiple vulnerabilities in the Cisco Discovery Protocol

Component Affected

ASR  9000  Series Aggregation Services Routers
•  Carrier  Routing  System (CRS)
• Firepower 4100 Series
• Firepower 9300  Security Appliances
•  MS XRy 9000  Router
• MDS 9000  Series  Multilayer Switches
• Network Convergence System  (NCS) 540  Series  Routers
• Network Convergence System  (NCS) 560  Series  Routers
• Network Convergence System  (NCS) 1000  Series
• Network  Convergence System (NCS) 5000  Series
• Network Convergence  System (NCS) 5500  Series
• Network  Convergence  System  (NCS) 6000  Series
• Nexus  1000  Virtual Edge  for VMware  vSphere
• Nexus  1000V Switch for Microsoft Hyper - V
• Nexus  1000V  Switch  for VMware vSphere
• Nexus  3000  Series Switches
• Nexus  5500  Platform  Switches
• Nexus  5600  Platform  Switches
• Nexus  6000  Series Switches
• Nexus  7000  Series Switches
• Nexus  9000  Series Fabric  Switches  in  Application Centric Infrastructure (AO) mode
• Nexus  9000  Series Switches  in  standalone NX-OS mode
• UCS 6200  Series Fabric  Interconnects
• UCS 6300  Series Fabric  Interconnects
• UCS 6400  Series Fabric  Interconnects
Overview
These vulnerabilities  have been reported in Cisco  Discovery Protocol  implementation  for Cisco  FXOS  Software, Cisco  IOS XR
Software, and Cisco NX-OS  Software  which could  allow an  unauthenticated,  adjacent  attacker  to execute  arbitrary code  or  cause
a  reload on an affected device.
Description
1. Remote Code Execution Vulnerability  ( CVE-2020-3119 )
A  vulnerability exists in  Cisco Discovery  Protocol implementation for Cisco NX-OS  Software due to the Cisco Discovery Protocol
parser does not properly validate input for certain fields in a Cisco Discovery  Protocol message that could allow an
unauthenticated,  adjacent attacker to execute arbitrary code or cause a  reload on an affected device. An attacker could exploit
this vulnerability by sending a  malicious  Cisco Discovery  Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to cause a  stack overflow, which could allow the attacker to
execute arbitrary code with administrative privileges on an affected device.
2. Denial of Service Vulnerability  ( CVE-2020-3120 )
A vulnerability  exists  in Cisco Discovery  Protocol implementation for Cisco  FXOS Software,  Cisco  IOS  XR Software, and Cisco
NX-OS  Software due to a missing check when the affected software processes  Cisco Discovery Protocol messages. That could
allow an attacker on the local network to execute code or cause a denial of service.  An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to exhaust system memory, causing the device to reload.

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Some Dark web Links

Cyber Security Audits