CVE-2020-3397 is a high-severity denial-of-service vulnerability affecting Cisco NX-OS Software's BGP MVPN implementation. It allows an unauthenticated, remote attacker to cause an affected device to reload by sending a specially crafted BGP MVPN update message. The attack requires an established BGP peer connection, implying the attacker must spoof or compromise a trusted BGP peer. While the CVSS score is 8.6, there is no known public exploit code, and it is not on CISA's KEV catalog, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.