CVE-2020-3512: Cisco IOS and IOS XE Software PROFINET Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of LLDP messages in the PROFINET LLDP message handler. An attacker could exploit this vulnerability by sending a malicious LLDP message to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3512?
CVE-2020-3512 has a severity rating of Medium since it allows an unauthenticated attacker to cause a denial of service condition on affected devices.
How do I fix CVE-2020-3512?
To mitigate CVE-2020-3512, you should upgrade to a Cisco IOS or IOS XE version that addresses this vulnerability.
What devices are affected by CVE-2020-3512?
CVE-2020-3512 affects various Cisco IOS and IOS XE devices, particularly those versions prior to the patched releases.
Can CVE-2020-3512 be exploited remotely?
CVE-2020-3512 can only be exploited by an adjacent attacker, meaning it requires physical or local network access.
What symptoms indicate an exploitation of CVE-2020-3512?
Exploitation of CVE-2020-3512 may lead to device crashes, resulting in loss of service or operational downtime.