First published: Wed Feb 05 2020(Updated: )
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Extensible Operating System | <=2.3.1.173 | |
Cisco Firepower Extensible Operating System | >=2.6<2.6.1.187 | |
Cisco Firepower Extensible Operating System | >=2.7<2.7.1.106 | |
Cisco FX-OS | =2.4 | |
Cisco Firepower 4110 Next-Generation Firewall | ||
Cisco Firepower 4115 | ||
Cisco Firepower 4120 Next-Generation Firewall | ||
Cisco Firepower 4125 firmware | ||
Cisco Firepower 4140 Next-Generation Firewall | ||
Cisco Firepower 4145 firmware | ||
Cisco Firepower 4150 Next-Generation Firewall | ||
Cisco Firepower 9300 firmware | ||
Cisco IOS XRv 9000 | =5.2.5 | |
Cisco NCS 6000 | ||
Cisco IOS XRv 9000 | =6.4.2 | |
Cisco ASR 9000v-v2 | ||
Cisco ASR 9001 | ||
Cisco ASR 9006 Router | ||
Cisco ASR 9010 Router | ||
Cisco ASR 9901-RP Firmware | ||
Cisco ASR 9904 | ||
Cisco ASR 9906 | ||
Cisco ASR 9910 | ||
Cisco ASR 9912 | ||
Cisco ASR 9922 | ||
Cisco Carrier Routing System | ||
Cisco IOS XRv 9000 | =6.5.3 | |
Cisco NCS 5001 Firmware | ||
Cisco NCS 5002 | ||
Cisco NCS 5011 | ||
Cisco NCS 540-12Z20G-SYS-A | ||
Cisco NCS 540-12Z20G-SYS-D | ||
Cisco NCS 540 | ||
Cisco NCS 540-28Z4C-SYS-A | ||
Cisco NCS 540-28Z4C-SYS-D | ||
Cisco NCS 540 | ||
Cisco NCS 540X-12Z16G-SYS-A | ||
Cisco NCS 540X-12Z16G-SYS-D | ||
Cisco NCS 540X-16Z4G8Q2C-A/D | ||
Cisco NCS 540X-16Z4G8Q2C-A/D | ||
Cisco NCS 540 | ||
Cisco NCS 5501-SE | ||
Cisco NCS 5501-SE | ||
Cisco NCS 5502 | ||
Cisco NCS 5502-SE Firmware | ||
Cisco NCS 5508 | ||
Cisco NCS 5516 | ||
Cisco NCS 560-4 | ||
Cisco IOS XRv 9000 | ||
Cisco IOS XRv 9000 | =6.6.25 | |
Cisco IOS XRv 9000 | =7.0.1 | |
Cisco NCS 540 | ||
Cisco NX-OS | >=5.2<6.2\(29\) | |
Cisco NX-OS | >=7.3<8.4\(1a\) | |
Cisco MDS 9132T | ||
Cisco MDS 9148S | ||
Cisco MDS 9148T | ||
Cisco MDS 9216 | ||
Cisco MDS 9216 | ||
Cisco MDS 9216 | ||
Cisco MDS 9222i | ||
Cisco MDS 9500 | ||
Cisco MDS 9500 | ||
Cisco MDS 9513 Firmware | ||
Cisco MDS 9706 Firmware | ||
Cisco MDS 9710 Firmware | ||
Cisco MDS 9718 Firmware | ||
Cisco NX-OS | >=5.2<5.2\(1\)sv5\(1.3\) | |
Cisco Nexus 1000V for VMware vSphere | ||
Cisco NX-OS | <=5.2 | |
Cisco Nexus 1000V for Hyper-V | ||
Cisco NX-OS | <5.2\(1\)sv3\(4.1b\) | |
Cisco Nexus 1000V | ||
Cisco NX-OS | >=7.0\(3\)f2<9.3\(2\) | |
Cisco NX-OS | >=7.0\(3\)i<7.0\(3\)i7\(8\) | |
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 3064 Firmware | ||
Cisco Nexus 3064 | ||
Cisco Nexus 31108PC-V Firmware | ||
Cisco Nexus 31108TC-V Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132C-Z Firmware | ||
Cisco Nexus 3132Q-XL | ||
Cisco Nexus 3132Q-V Firmware | ||
Cisco Nexus 3132Q-XL Firmware | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172 Firmware | ||
Cisco Nexus 3172PQ-XL Firmware | ||
Cisco Nexus 3172TQ Firmware | ||
Cisco Nexus 3172TQ-XL | ||
Cisco Nexus 3172TQ-XL Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264C-E Firmware | ||
Cisco Nexus 3264Q Firmware | ||
Cisco Nexus 3408-S Firmware | ||
Cisco Nexus 34180YC Firmware | ||
Cisco Nexus 3432D-S Firmware | ||
Cisco Nexus 3464C Firmware | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3524-XL Firmware | ||
Cisco Nexus 3548-X/XL Firmware | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 36180YC-R Firmware | ||
Cisco Nexus 3636C-R Firmware | ||
Cisco NX-OS Nexus 9000 Series | ||
Cisco Nexus 92160YC Switch | ||
Cisco Nexus 92300YC Firmware | ||
Cisco Nexus 92304QC Switch | ||
Cisco Nexus 92348GC-X Switch | ||
Cisco Nexus 9236C Switch | ||
Cisco Nexus 9272Q Switch | ||
Cisco Nexus | ||
Cisco Nexus 93108TC-FX Switch | ||
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128 Firmware | ||
Cisco Nexus 93180LC-EX Switch | ||
Cisco Nexus 93180YC-EX-24 | ||
Cisco Nexus 93180YC-FX Firmware | ||
Cisco Nexus 93216TC-FX2 Firmware | ||
Cisco Nexus 93240YC-FX2 Firmware | ||
Cisco Nexus 9332C Firmware | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus 93360YC-FX2 | ||
Cisco Nexus 9336C-FX2 Firmware | ||
Cisco Nexus N9336PQ-X | ||
Cisco Nexus 9348GC-FXP Firmware | ||
Cisco Nexus 9364c-h1 | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372PX-E Firmware | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9372TX-E Switch | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9504 firmware | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 firmware | ||
Cisco NX-OS | <7.3\(6\)n1\(1\) | |
Cisco Nexus 5548P Firmware | ||
Cisco Nexus 5548UP Firmware | ||
Cisco Nexus 5596T Firmware | ||
Cisco Nexus 5596UP Firmware | ||
Cisco 56128p | ||
Cisco Nexus 5624Q Firmware | ||
Cisco Nexus 5648Q Firmware | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5696Q Firmware | ||
Cisco NX-OS | <6.2\(24\) | |
Cisco NX-OS | >=7.2<7.3\(5\)d1\(1\) | |
Cisco NX-OS | >=8.0<8.2\(5\) | |
Cisco NX-OS | >=8.3<8.4\(2\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7700 series | ||
Cisco NX-OS | <13.2\(9b\) | |
Cisco NX-OS | >=14.0<14.2\(1j\) | |
Cisco UCS Manager | <3.2\(3m\) | |
Cisco UCS Manager | >=4.0<4.0\(4g\) | |
Cisco UCS 6248UP | ||
Cisco UCS 6296UP | ||
Cisco UCS 6300 firmware | ||
Cisco UCS 6324 firmware | ||
Cisco UCS 64108 | ||
Cisco UCS 6454 Fabric Interconnect |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3120 has been classified with a high severity level due to its potential to cause a denial of service (DoS).
To mitigate CVE-2020-3120, upgrade affected Cisco FXOS, IOS XR, or NX-OS software to a version that includes the security fix.
CVE-2020-3120 affects Cisco FXOS, IOS XR, and NX-OS software on specific versions, including Cisco Firepower Extensible Operating System.
CVE-2020-3120 cannot be exploited remotely as it requires an unauthenticated adjacent attacker.
CVE-2020-3120 can cause a device reload leading to a denial of service, affecting network availability.