CVE-2020-3118

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

References

http://packetstormsecurity.com/files/156203/Cisco-Discovery-Protocol-CDP-Remote-Device-Takeover.html

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200205-iosxr-cdp-rce

Details

Source: MITRE

Published: 2020-02-05

Updated: 2020-02-10

Type: CWE-134

Risk Information

CVSS v2

Base Score: 8.3

Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 6.5

Severity: HIGH

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*

cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*

Configuration 2

AND

OR

cpe:2.3:o:cisco:ios_xr:6.5.2:*:*:*:*:*:*:*

OR

cpe:2.3:h:cisco:asr_9000v:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9001:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9006:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9010:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9901:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9904:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9906:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9910:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9912:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:asr_9922:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:crs:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_1001:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_1002:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_1004:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_520:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-12z20g-sys-a:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-12z20g-sys-d:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-24z8q2c-sys:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-28z4c-sys-a:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-28z4c-sys-d:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540-acc-sys:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540x-12z16g-sys-a:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540x-12z16g-sys-d:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540x-16z4g8q2c-a:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540x-16z4g8q2c-d:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540x-acc-sys:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5501:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5501-se:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5502:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5502-se:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5508:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5516:-:*:*:*:*:*:*:*

Configuration 3

AND

OR

cpe:2.3:o:cisco:ios_xr:5.2.5:*:*:*:*:*:*:*

OR

cpe:2.3:h:cisco:ncs_6000:-:*:*:*:*:*:*:*

Configuration 4

AND

OR

cpe:2.3:o:cisco:ios_xr:6.5.3:*:*:*:*:*:*:*

OR

cpe:2.3:h:cisco:ncs_5001:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5002:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_5011:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:ncs_540:-:*:*:*:*:*:*:*

cpe:2.3:h:cisco:xrv_9000:-:*:*:*:*:*:*:*

Configuration 5

AND

OR

cpe:2.3:o:cisco:ios_xr:6.6.25:*:*:*:*:*:*:*

OR

cpe:2.3:h:cisco:ncs_560:-:*:*:*:*:*:*:*

Configuration 6

AND

OR

cpe:2.3:o:cisco:ios_xr:7.0.1:*:*:*:*:*:*:*

OR

cpe:2.3:h:cisco:ncs_540l:-:*:*:*:*:*:*:*

Tenable Plugins

View all (2 total)

IDNameProductFamilySeverity
701265Cisco IOS XR Software Cisco Discovery Protocol RCE (cisco-sa-20200205-iosxr-cdp-rce)Nessus Network MonitorSNMP
high
133603Cisco IOS XR Software Cisco Discovery Protocol Remote Code Execution Vulnerability (cisco-sa-20200205-iosxr-cdp-rce)NessusCISCO
high