Vulnerability Description
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 8.1\(1\) |
| Cisco | Mds 9132T | - |
| Cisco | Mds 9148S | - |
| Cisco | Mds 9148T | - |
| Cisco | Mds 9216 | - |
| Cisco | Mds 9216A | - |
| Cisco | Mds 9216I | - |
| Cisco | Mds 9222I | - |
| Cisco | Mds 9506 | - |
| Cisco | Mds 9509 | - |
| Cisco | Mds 9513 | - |
| Cisco | Mds 9706 | - |
| Cisco | Mds 9710 | - |
| Cisco | Mds 9718 | - |
| Cisco | Nexus 3016 | - |
| Cisco | Nexus 3048 | - |
| Cisco | Nexus 3064 | - |
| Cisco | Nexus 3064-T | - |
| Cisco | Nexus 31108Pc-V | - |
| Cisco | Nexus 31108Tc-V | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2020-3174?
CVE-2020-3174 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. T...
How severe is CVE-2020-3174?
CVE-2020-3174 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3174?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Mds 9132T, Cisco Mds 9148S, Cisco Mds 9148T, Cisco Mds 9216.