CVE-2020-3174
published 2020-02-26CVE-2020-3174: A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid…
PriorityP421medium4.7CVSS 3.1
AVAACLPRNUINSCCNILAN
EPSS
0.29%
21.4th percentile
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software_7.3_d1 | >= unspecified < n/a | n/a |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
vendor_cisco·2020-02-26·CVSS 4.7
CVE-2020-3174 [MEDIUM] CWE-345 Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet.
The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions.
Cisco has released software updates that address this vulnerability. There are no work
Cisco
Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3174 Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
CVE-2020-3174: Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions. Cisco has released software updates that address this vulnerability. Ther
GHSA
GHSA-44pg-r8gr-j75x: A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn in
ghsa_unreviewed·2022-05-24
CVE-2020-3174 [LOW] GHSA-44pg-r8gr-j75x: A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn in
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-26
Published