CVE-2020-3118
Last modified
CVE-2020-3118 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. CISA has confirmed active exploitation in the wild. EPSS estimates a 11.81% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | >= 6.6.0, < 6.6.12 |
| Cisco | Ios Xr | >= 7.0.0, < 7.0.2 |
| Cisco | Ios Xr | 6.5.3 |
| Cisco | Ios Xr | 5.2.5 |
| Cisco | Ios Xr | 6.4.2 |
| Cisco | Ios Xr | 6.6.25 |
| Cisco | Ios Xr | 7.0.1 |
References
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.htmlThird Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3118US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-3118?
How severe is CVE-2020-3118?
How do I fix CVE-2020-3118?
Are you affected by CVE-2020-3118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
