CVE-2020-3398 is a high-severity vulnerability in Cisco NX-OS Software's BGP MVPN implementation, allowing an unauthenticated, remote attacker to cause BGP session resets and a partial denial of service. The vulnerability stems from incorrect parsing of a specific BGP MVPN update message. A successful exploit, requiring an attacker to spoof a trusted BGP peer, could lead to BGP route instability and impact traffic. While no public exploit code exists and it's not actively exploited, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.