Vulnerability Description
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Firepower Extensible Operating System | <= 2.3.1.173 |
| Cisco | Fxos | 2.4 |
| Cisco | Firepower 4110 | - |
| Cisco | Firepower 4115 | - |
| Cisco | Firepower 4120 | - |
| Cisco | Firepower 4125 | - |
| Cisco | Firepower 4140 | - |
| Cisco | Firepower 4145 | - |
| Cisco | Firepower 4150 | - |
| Cisco | Firepower 9300 | - |
| Cisco | Ios Xr | 5.2.5 |
| Cisco | Ncs 6000 | - |
| Cisco | Asr 9000V | - |
| Cisco | Asr 9001 | - |
| Cisco | Asr 9006 | - |
| Cisco | Asr 9010 | - |
| Cisco | Asr 9901 | - |
| Cisco | Asr 9904 | - |
| Cisco | Asr 9906 | - |
| Cisco | Asr 9910 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2020-3120?
CVE-2020-3120 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a rel...
How severe is CVE-2020-3120?
CVE-2020-3120 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3120?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Firepower Extensible Operating System, Cisco Fxos, Cisco Firepower 4110, Cisco Firepower 4115, Cisco Firepower 4120.