SB2020082722 - Multiple vulnerabilities in Cisco NX-OS Software
Published: August 27, 2020 Updated: August 27, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2020-3338)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing inbound PIM6 packets. A remote attacker can send multiple specially crafted PIM6 packets, trigger resource exhaustion and perform a denial of service (DoS) attack.
2) Input validation error (CVE-ID: CVE-2020-3398)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation due to incorrect parsing of a specific type of BGP MVPN update message. A remote attacker can send this BGP MVPN update message and perform a denial of service (DoS) attack.
3) Input validation error (CVE-ID: CVE-2020-3397)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation due to incomplete input validation of a specific type of BGP MVPN update message. A remote attacker can send a specially crafted BGP MVPN update message and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-pim-memleak-dos-tC8eP7uw
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-mvpn-dos-K8kbCrJp
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-nlri-dos-458rG2OQ