CVE-2020-3512 - CERT CVE
ID CVE-2020-3512
Sažetak A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of LLDP messages in the PROFINET LLDP message handler. An attacker could exploit this vulnerability by sending a malicious LLDP message to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
Reference
CVSS
Base: 5.7
Impact: 6.9
Exploitability:5.5
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE COMPLETE
CVSS vektor AV:A/AC:M/Au:N/C:N/I:N/A:C
Zadnje važnije ažuriranje 08-10-2020 - 14:03
Objavljeno 24-09-2020 - 18:15