CVE-2020-3479 is a denial-of-service vulnerability affecting Cisco IOS and IOS XE Software, specifically in the Multiprotocol Border Gateway Protocol (MP-BGP) implementation for Layer 2 VPN (L2VPN) Ethernet VPN (EVPN). An unauthenticated, remote attacker can exploit this by sending crafted BGP update messages with malformed EVPN attributes, causing the affected device to crash. Rated 7.5 HIGH on CVSS, it has a low attack complexity and requires no user interaction, leading to a complete loss of availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.