CVE-2020-3119: Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability
A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3119?
CVE-2020-3119 has a high severity rating due to its potential to allow arbitrary code execution by an unauthenticated adjacent attacker.
How do I fix CVE-2020-3119?
To mitigate CVE-2020-3119, upgrade your affected Cisco NX-OS Software to a version that is not vulnerable according to the Cisco security advisory.
Who is affected by CVE-2020-3119?
CVE-2020-3119 affects multiple versions of Cisco NX-OS Software that do not parse Cisco Discovery Protocol properly.
What is CVE-2020-3119?
CVE-2020-3119 is a vulnerability in the Cisco Discovery Protocol implementation that can be exploited for remote code execution on affected Cisco devices.
Can CVE-2020-3119 be exploited remotely?
Yes, CVE-2020-3119 can be exploited by nearby attackers, making it necessary to secure physical access to affected devices.