A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request. An attacker could exploit this vulnerability by sending a malicious GARP packet on the local subnet to cause the ARP table on the device to become corrupted. A successful exploit could allow the attacker to populate the ARP table with incorrect entries, which could lead to traffic disruptions.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-nxos-arp | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2020-02-26 17:15
Updated : 2024-02-04 20:39
NVD link : CVE-2020-3174
Mitre link : CVE-2020-3174
CVE.ORG link : CVE-2020-3174
JSON object : View
Products Affected
cisco
- mds_9710
- nexus_3172
- mds_9216a
- nexus_3264c-e
- nexus_9396px
- nexus_31108tc-v
- nexus_9372px
- nexus_3172pq-xl
- nexus_3548-xl
- mds_9509
- nexus_93360yc-fx2
- nexus_3432d-s
- nexus_3164q
- nexus_3064
- nexus_9336c-fx2
- nexus_9336pq_aci_spine
- nexus_93108tc-fx
- nexus_93216tc-fx2
- nexus_7000
- nexus_92160yc-x
- nexus_93128tx
- nexus_9508
- nexus_9332c
- mds_9148s
- nexus_93180lc-ex
- nexus_3264q
- mds_9216i
- nexus_9348gc-fxp
- nexus_3048
- mds_9706
- nexus_3132q
- nexus_3132c-z
- nexus_9364c
- nexus_92300yc
- nexus_9000v
- nexus_9272q
- mds_9216
- nexus_3408-s
- nexus_3016
- nexus_9372tx-e
- nexus_9516
- nexus_93180yc-fx
- mds_9132t
- nexus_9396tx
- nexus_3172tq-xl
- mds_9513
- mds_9718
- nexus_9372tx
- mds_9148t
- nexus_3548-x
- nexus_3524
- nexus_3464c
- nexus_31108pc-v
- nx-os
- nexus_3132q-v
- mds_9222i
- nexus_3064-t
- nexus_93120tx
- nexus_3132q-xl
- nexus_9372px-e
- nexus_36180yc-r
- nexus_92348gc-x
- nexus_3636c-r
- nexus_93108tc-ex
- nexus_93240yc-fx2
- nexus_3232c_
- nexus_31128pq
- nexus_7700
- nexus_3172tq
- nexus_34180yc
- nexus_3524-x
- nexus_92304qc
- nexus_9504
- nexus_9236c
- nexus_93180yc-ex
- nexus_9332pq
- nexus_3548
- mds_9506
- nexus_3172tq-32t
- nexus_3524-xl
CWE
CWE-345
Insufficient Verification of Data Authenticity