CVE-2020-3118
Last modified
CVE-2020-3118 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. CISA has confirmed active exploitation in the wild. EPSS estimates a 11.81% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | >= 6.6.0, < 6.6.12 |
| Cisco | Ios Xr | >= 7.0.0, < 7.0.2 |
| Cisco | Ios Xr | 6.5.3 |
| Cisco | Ios Xr | 5.2.5 |
| Cisco | Ios Xr | 6.4.2 |
| Cisco | Ios Xr | 6.6.25 |
| Cisco | Ios Xr | 7.0.1 |
References
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.htmlThird Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-3118US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-3118?
How severe is CVE-2020-3118?
How do I fix CVE-2020-3118?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-3112A vulnerability in the REST API endpoint of Cisco Data Cente…8.8
- CVE-2020-3113A vulnerability in the web-based management interface of Cis…5.4
- CVE-2020-3114A vulnerability in the web-based management interface of Cis…8.8
- CVE-2020-3115A vulnerability in the CLI of the Cisco SD-WAN Solution vMan…8.8
- CVE-2020-3116A vulnerability in the way Cisco Webex applications process …5.5
- CVE-2020-3117A vulnerability in the API Framework of Cisco AsyncOS for Ci…4.7
- CVE-2020-3119A vulnerability in the Cisco Discovery Protocol implementati…8.8
- CVE-2020-3120A vulnerability in the Cisco Discovery Protocol implementati…6.5
- CVE-2020-3121A vulnerability in the web-based management interface of Cis…6.1
- CVE-2020-3122A vulnerability in the web-based management interface of Cis…5.3
- CVE-2020-3123A vulnerability in the Data-Loss-Prevention (DLP) module in …7.5
- CVE-2020-3124A vulnerability in the web-based interface of Cisco Hosted C…6.5
Are you affected by CVE-2020-3118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
