Multiple vulnerabilities in the Cisco Discovery Protocol
Component Affected
1. Remote Code Execution Vulnerability ( CVE-2020-3119 )
A vulnerability exists in Cisco Discovery Protocol implementation for Cisco NX-OS Software due to the Cisco Discovery Protocol
parser does not properly validate input for certain fields in a Cisco Discovery Protocol message that could allow an
unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. An attacker could exploit
this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to cause a stack overflow, which could allow the attacker to
execute arbitrary code with administrative privileges on an affected device.
2. Denial of Service Vulnerability ( CVE-2020-3120 )
A vulnerability exists in Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco
NX-OS Software due to a missing check when the affected software processes Cisco Discovery Protocol messages. That could
allow an attacker on the local network to execute code or cause a denial of service. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to exhaust system memory, causing the device to reload.
• ASR 9000 Series Aggregation Services Routers
• Carrier Routing System (CRS)
• Firepower 4100 Series
• Firepower 9300 Security Appliances
• MS XRy 9000 Router
• MDS 9000 Series Multilayer Switches
• Network Convergence System (NCS) 540 Series Routers
• Network Convergence System (NCS) 560 Series Routers
• Network Convergence System (NCS) 1000 Series
• Network Convergence System (NCS) 5000 Series
• Network Convergence System (NCS) 5500 Series
• Network Convergence System (NCS) 6000 Series
• Nexus 1000 Virtual Edge for VMware vSphere
• Nexus 1000V Switch for Microsoft Hyper - V
• Nexus 1000V Switch for VMware vSphere
• Nexus 3000 Series Switches
• Nexus 5500 Platform Switches
• Nexus 5600 Platform Switches
• Nexus 6000 Series Switches
• Nexus 7000 Series Switches
• Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AO) mode
• Nexus 9000 Series Switches in standalone NX-OS mode
• UCS 6200 Series Fabric Interconnects
• UCS 6300 Series Fabric Interconnects
• UCS 6400 Series Fabric Interconnects
Overview
These vulnerabilities have been reported in Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR
Software, and Cisco NX-OS Software which could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause
a reload on an affected device.
Description• Carrier Routing System (CRS)
• Firepower 4100 Series
• Firepower 9300 Security Appliances
• MS XRy 9000 Router
• MDS 9000 Series Multilayer Switches
• Network Convergence System (NCS) 540 Series Routers
• Network Convergence System (NCS) 560 Series Routers
• Network Convergence System (NCS) 1000 Series
• Network Convergence System (NCS) 5000 Series
• Network Convergence System (NCS) 5500 Series
• Network Convergence System (NCS) 6000 Series
• Nexus 1000 Virtual Edge for VMware vSphere
• Nexus 1000V Switch for Microsoft Hyper - V
• Nexus 1000V Switch for VMware vSphere
• Nexus 3000 Series Switches
• Nexus 5500 Platform Switches
• Nexus 5600 Platform Switches
• Nexus 6000 Series Switches
• Nexus 7000 Series Switches
• Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AO) mode
• Nexus 9000 Series Switches in standalone NX-OS mode
• UCS 6200 Series Fabric Interconnects
• UCS 6300 Series Fabric Interconnects
• UCS 6400 Series Fabric Interconnects
Overview
These vulnerabilities have been reported in Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR
Software, and Cisco NX-OS Software which could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause
a reload on an affected device.
1. Remote Code Execution Vulnerability ( CVE-2020-3119 )
A vulnerability exists in Cisco Discovery Protocol implementation for Cisco NX-OS Software due to the Cisco Discovery Protocol
parser does not properly validate input for certain fields in a Cisco Discovery Protocol message that could allow an
unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. An attacker could exploit
this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to cause a stack overflow, which could allow the attacker to
execute arbitrary code with administrative privileges on an affected device.
2. Denial of Service Vulnerability ( CVE-2020-3120 )
A vulnerability exists in Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco
NX-OS Software due to a missing check when the affected software processes Cisco Discovery Protocol messages. That could
allow an attacker on the local network to execute code or cause a denial of service. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device.
Successful exploitation of this vulnerability could allow the attacker to exhaust system memory, causing the device to reload.
Comments
Post a Comment