Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3172


A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to a Layer 2-adjacent affected device. A successful exploit could allow the attacker to cause a buffer overflow that could allow the attacker to execute arbitrary code as root or cause a DoS condition on the affected device. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Note: This vulnerability is different from the following Cisco FXOS and NX-OS Software Cisco Discovery Protocol vulnerabilities that Cisco announced on Feb. 5, 2020: Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability and Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability.


Published

2020-02-26T17:15:13.343

Last Modified

2024-11-21T05:30:28.670

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco firepower_extensible_operating_system < 2.6.1.187 Yes
Operating System cisco firepower_extensible_operating_system < 2.7.1.106 Yes
Hardware cisco firepower_4110 - No
Hardware cisco firepower_4115 - No
Hardware cisco firepower_4120 - No
Hardware cisco firepower_4125 - No
Hardware cisco firepower_4140 - No
Hardware cisco firepower_4145 - No
Hardware cisco firepower_4150 - No
Hardware cisco firepower_9300 - No
Application cisco ucs_manager < 3.2\(3n\) Yes
Application cisco ucs_manager < 4.0\(4g\) Yes
Hardware cisco ucs_6248up - No
Hardware cisco ucs_6296up - No
Hardware cisco ucs_6324 - No
Hardware cisco ucs_6332 - No
Hardware cisco ucs_6332-16up - No
Operating System cisco nx-os - Yes
Hardware cisco mds_9132t - No
Hardware cisco mds_9148s - No
Hardware cisco mds_9148t - No
Hardware cisco mds_9216 - No
Hardware cisco mds_9216a - No
Hardware cisco mds_9216i - No
Hardware cisco mds_9222i - No
Hardware cisco mds_9506 - No
Hardware cisco mds_9509 - No
Hardware cisco mds_9513 - No
Hardware cisco mds_9706 - No
Hardware cisco mds_9710 - No
Hardware cisco mds_9718 - No
Operating System cisco nx-os 5.2\(1\)sv5\(1.2\) Yes
Operating System cisco nx-os 5.2\(1\)sv5\(1.2\) Yes
Hardware cisco nexus_1000v - No
Hardware cisco nexus_1000ve - No
Operating System cisco nx-os - Yes
Hardware cisco nexus_3016 - No
Hardware cisco nexus_3048 - No
Hardware cisco nexus_3064 - No
Hardware cisco nexus_3064-t - No
Hardware cisco nexus_31108pc-v - No
Hardware cisco nexus_31108tc-v - No
Hardware cisco nexus_31128pq - No
Hardware cisco nexus_3132c-z - No
Hardware cisco nexus_3132q - No
Hardware cisco nexus_3132q-v - No
Hardware cisco nexus_3132q-xl - No
Hardware cisco nexus_3164q - No
Hardware cisco nexus_3172 - No
Hardware cisco nexus_3172pq-xl - No
Hardware cisco nexus_3172tq - No
Hardware cisco nexus_3172tq-32t - No
Hardware cisco nexus_3172tq-xl - No
Hardware cisco nexus_3232c_ - No
Hardware cisco nexus_3264c-e - No
Hardware cisco nexus_3264q - No
Hardware cisco nexus_3408-s - No
Hardware cisco nexus_34180yc - No
Hardware cisco nexus_3432d-s - No
Hardware cisco nexus_3464c - No
Hardware cisco nexus_3524 - No
Hardware cisco nexus_3524-x - No
Hardware cisco nexus_3524-xl - No
Hardware cisco nexus_3548 - No
Hardware cisco nexus_3548-x - No
Hardware cisco nexus_3548-xl - No
Hardware cisco nexus_36180yc-r - No
Hardware cisco nexus_3636c-r - No
Operating System cisco nx-os 7.3\(5\)n1\(1\) Yes
Hardware cisco nexus_5010 - No
Hardware cisco nexus_5020 - No
Hardware cisco nexus_5548p - No
Hardware cisco nexus_5548up - No
Hardware cisco nexus_5596t - No
Hardware cisco nexus_5596up - No
Hardware cisco nexus_56128p - No
Hardware cisco nexus_5624q - No
Hardware cisco nexus_5648q - No
Hardware cisco nexus_5672up - No
Hardware cisco nexus_5696q - No
Operating System cisco nx-os - Yes
Hardware cisco nexus_6001 - No
Hardware cisco nexus_6004 - No
Operating System cisco nx-os 7.3\(0\)d1\(0.140\) Yes
Operating System cisco nx-os 7.3\(0\)d1\(0.146\) Yes
Hardware cisco nexus_7000 - No
Hardware cisco nexus_7700 - No
Operating System cisco nx-os 7.0\(3\)i3\(0.191\) Yes
Operating System cisco nx-os 13.2\(7.230\) Yes
Operating System cisco nx-os 14.2\(1i\) Yes
Hardware cisco nexus_92304qc - No
Hardware cisco nexus_92348gc-x - No
Hardware cisco nexus_9236c - No
Hardware cisco nexus_9272q - No
Hardware cisco nexus_93108tc-ex - No
Hardware cisco nexus_93108tc-fx - No
Hardware cisco nexus_93120tx - No
Hardware cisco nexus_93128tx - No
Hardware cisco nexus_93180lc-ex - No
Hardware cisco nexus_93180yc-ex - No
Hardware cisco nexus_93180yc-fx - No
Hardware cisco nexus_93216tc-fx2 - No
Hardware cisco nexus_93240yc-fx2 - No
Hardware cisco nexus_9332c - No
Hardware cisco nexus_9332pq - No
Hardware cisco nexus_93360yc-fx2 - No
Hardware cisco nexus_9336c-fx2 - No
Hardware cisco nexus_9336pq_aci_spine - No
Hardware cisco nexus_9348gc-fxp - No
Hardware cisco nexus_9364c - No
Hardware cisco nexus_9372px - No
Hardware cisco nexus_9372px-e - No
Hardware cisco nexus_9372tx - No
Hardware cisco nexus_9372tx-e - No
Hardware cisco nexus_9396px - No
Hardware cisco nexus_9396tx - No
Hardware cisco nexus_9504 - No
Hardware cisco nexus_9508 - No
Hardware cisco nexus_9516 - No

References