First published: Thu Aug 27 2020(Updated: )
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of a specific type of BGP MVPN update message. An attacker could exploit this vulnerability by sending this specific, valid BGP MVPN update message to a targeted device. A successful exploit could allow the attacker to cause one of the BGP-related routing applications to restart multiple times, leading to a system-level restart. Note: The Cisco implementation of BGP accepts incoming BGP traffic from only explicitly configured peers. To exploit this vulnerability, an attacker must send a specific BGP MVPN update message over an established TCP connection that appears to come from a trusted BGP peer. To do so, the attacker must obtain information about the BGP peers in the trusted network of the affected system.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | ||
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 3064x | ||
Cisco Nexus 3064 | ||
Cisco Nexus 31108PV-V | ||
Cisco Nexus 31108TC-V Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132C-Z Firmware | ||
Cisco Nexus 3132Q-XL | ||
Cisco Nexus 3132Q-V Firmware | ||
Cisco Nexus 3132Q-X/3132Q-XL | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172 | ||
Cisco Nexus 3172PQ/PQ-XL | ||
Cisco Nexus 3172TQ Firmware | ||
Cisco Nexus 3172TQ-XL | ||
Cisco Nexus 3172TQ-XL Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264C-E Firmware | ||
Cisco Nexus 3264Q Firmware | ||
Cisco Nexus 3408-S Firmware | ||
Cisco Nexus 34180YC Firmware | ||
Cisco Nexus 3432D-S Firmware | ||
Cisco Nexus 3464C Firmware | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3524-x/xl | ||
Cisco Nexus 3548-X/XL Firmware | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 36180YC-R Firmware | ||
Cisco Nexus 3636C-R Firmware | ||
Cisco Nexus 92160YC Switch | ||
Cisco Nexus 92300YC Switch | ||
Cisco Nexus 92304qc | ||
Cisco Nexus 92348GC-X Switch | ||
Cisco Nexus 9236c | ||
Cisco Nexus 9272Q Switch | ||
Cisco Nexus Series | ||
Cisco Nexus 93108TC-FX Switch | ||
Cisco Nexus 93120tx | ||
Cisco Nexus 93128tx | ||
Cisco Nexus 93180LC-EX Switch | ||
Cisco Nexus 93180YC-EX | ||
Cisco Nexus 93180YC-FX Firmware | ||
Cisco Nexus 93216TC-FX2 Firmware | ||
Cisco Nexus 93240YC-FX2 Firmware | ||
Cisco Nexus 9332C Firmware | ||
Cisco Nexus 9332pq | ||
Cisco Nexus 93360YC-FX2 | ||
Cisco Nexus 9336C-FX2 Firmware | ||
Cisco Nexus N9336PQ-X | ||
Cisco Nexus 9348GC-FXP Firmware | ||
Cisco Nexus 9364C-GX Firmware | ||
Cisco Nexus 9372px | ||
Cisco Nexus 9372PX-E Switch | ||
Cisco Nexus 9372tx | ||
Cisco Nexus 9372TX-E Switch | ||
Cisco Nexus 9396px | ||
Cisco Nexus 9396tx | ||
Cisco Nexus 9504 | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3397 is a vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Cisco Nexus devices running Cisco NX-OS Software are affected by CVE-2020-3397.
CVE-2020-3397 has a severity rating of 8.6 (high).
To fix CVE-2020-3397, Cisco recommends upgrading to a fixed software release.
More information about CVE-2020-3397 can be found on the Cisco Security Advisory page.