CVE-2020-3168 describes a denial-of-service vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere and Cisco NX-OS. An unauthenticated, remote attacker can exploit this by initiating a high volume of failed CLI login attempts, causing the Virtual Supervisor Module (VSM) to become inaccessible. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity leading to a complete loss of availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2\(1\)sv3\(4.1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:5.2\(1\)sv3\(4.1a\):*:*:*:*:vsphere:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.