Vulnslist

find the latest Cisco vulnerabilities

Cisco MDS 9000 Series Switches Denial of Service Vulnerability

cisco-sa-20200226-mds-ovrld-dos · High · Published · Updated

A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource usage control. An attacker could exploit this vulnerability by sending traffic to the management interface (mgmt0) of an affected device at very high rates. An exploit could allow the attacker to cause unexpected behaviors such as high CPU usage, process crashes, or even full system reboots of an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-mds-ovrld-dos This advisory is part of the February 2020 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication, which includes six Cisco Security Advisories that describe six vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: February 2020 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2020-3175
Cisco Bug IDsCSCvo26707
CVSS ScoreBase 8.6
Base 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco NX-OS Software 7.3(0)D1(1), Cisco NX-OS Software 7.3(0)DY(1), Cisco NX-OS Software 7.3(1)D1(1), Cisco NX-OS Software 7.3(1)DY(1), Cisco NX-OS Software, Cisco MDS 9000 Multilayer Directors and Fabric Switches

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2020-3175 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2020-3175 Cisco OpenVuln
Cisco MDS 9000 Family of Multilayer Switches CVE-2020-3175 Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) CVE-2020-3175 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2020-3175 Cisco OpenVuln
Cisco NX-OS Software CVE-2020-3175 Cisco OpenVuln
Cisco MDS 9000 Multilayer Directors and Fabric Switches CVE-2020-3175 Cisco OpenVuln