CVE-2020-3228: Cisco IOS, IOS XE, and NX-OS Software Security Group Tag Exchange Protocol Denial of Service Vulnerability
A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because crafted SXP packets are mishandled. An attacker could exploit this vulnerability by sending specifically crafted SXP packets to the affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3228?
CVE-2020-3228 is rated as a critical denial of service vulnerability.
How do I fix CVE-2020-3228?
To resolve CVE-2020-3228, you should apply the latest available patches provided by Cisco for affected devices.
What are the affected devices for CVE-2020-3228?
CVE-2020-3228 impacts specific versions of Cisco IOS, IOS XE, and NX-OS software.
What could an attacker do using CVE-2020-3228?
An unauthorized remote attacker could exploit CVE-2020-3228 to cause the affected device to reload, resulting in a denial of service.
Is there a workaround for CVE-2020-3228?
Cisco has not provided a specific workaround for CVE-2020-3228, making it essential to apply the recommended patches.