CVE-2020-3338 is a denial-of-service vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) within Cisco NX-OS Software. An unauthenticated, remote attacker can exploit this flaw by sending crafted PIM6 packets, leading to a memory leak in the PIM6 application. This memory leak can eventually cause the application to cease processing legitimate traffic, resulting in a denial of service on the affected device. The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is no user interaction required for a successful exploit. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there has been some community discussion and media coverage, the EPSS score suggests a low likelihood of exploitation compared to other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.