ID |
CVE-2020-3174
|
Sažetak |
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions. |
Reference |
|
CVSS |
Base: | 3.3 |
Impact: | 2.9 |
Exploitability: | 6.5 |
|
Pristup |
Vektor | Složenost | Autentikacija |
ADJACENT_NETWORK |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
PARTIAL |
NONE |
|
CVSS vektor |
AV:A/AC:L/Au:N/C:N/I:P/A:N |
Zadnje važnije ažuriranje |
03-03-2020 - 20:46 |
Objavljeno |
26-02-2020 - 17:15 |