3.3
CVSSv2

CVE-2020-3174

Published: 26/02/2020 Updated: 03/03/2020
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent malicious user to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the malicious user to populate the ARP table with incorrect entries, which could lead to traffic disruptions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nx-os 8.1\\(1\\)

cisco nx-os 8.4\\(1\\)

cisco nx-os 9.3\\(1\\)

Vendor Advisories

A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries The ARP entries are for nonlocal IP addresses for the subnet The vulnerability is due to improper validation of a received gratuitous ARP (GARP) reque ...