CVE-2020-3118
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco IOS XR Software Discovery Protocol Format String Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 12% (אחוזון 100) נכון ל-10/8/2026
- CWE
- CWE-134, CWE-787
מוצרים מושפעים
cisco: ios xr; cisco: asr 9000v; cisco: asr 9001; cisco: asr 9006; cisco: asr 9010; cisco: asr 9901; cisco: asr 9904; cisco: asr 9906; cisco: asr 9910; cisco: asr 9912; cisco: asr 9922; cisco: ncs 540-12z20g-sys-a; cisco: ncs 540-12z20g-sys-d; cisco: ncs 540-24z8q2c-sys; cisco: ncs 540-28z4c-sys-a
קישורים
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa… Vendor Advisory
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remot… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remot… Third Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource