CVE-2020-3479: Cisco IOS and IOS XE Software MP-BGP EVPN Denial of Service Vulnerability
A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of Border Gateway Protocol (BGP) update messages that contain crafted EVPN attributes. An attacker could exploit this vulnerability by sending BGP update messages with specific, malformed attributes to an affected device. A successful exploit could allow the attacker to cause an affected device to crash, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3479?
CVE-2020-3479 is a vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software.
What is the severity of CVE-2020-3479?
The severity of CVE-2020-3479 is high, with a CVSS score of 7.5.
How does CVE-2020-3479 affect Cisco devices?
CVE-2020-3479 affects Cisco IOS Software and Cisco IOS XE Software.
What is the impact of CVE-2020-3479?
CVE-2020-3479 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
How can I fix CVE-2020-3479?
To fix CVE-2020-3479, it is recommended to apply the necessary updates and patches provided by Cisco.