CVE-2020-3517 is a denial-of-service vulnerability in the Cisco Fabric Services component of Cisco FXOS and NX-OS Software. An unauthenticated attacker can exploit insufficient error handling when parsing Cisco Fabric Services messages, leading to process crashes and device reloads. This vulnerability has a CVSS score of 8.6 (High) and can be exploited remotely or adjacently, depending on configuration. While no public exploit code or active exploitation has been observed, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1, < 1.1.4.179CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.0.1.153CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 2.1, < 2.1.1.86CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 2.2, < 2.2.1.70CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
6.0\(2\)a3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:6.0\(2\)a3\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.