CVE-2020-3170
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
Published:Feb 26, 2020
Last Modified:Nov 21, 2024
EPS:Feb 26, 2020
EPSS Score:0.004
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Mds 9132t
Cisco
Mds 9132t
Vendor
Cisco
Product
Mds 9148s
Cisco
Mds 9148s
Vendor
Cisco
Product
Mds 9148t
Cisco
Mds 9148t
Vendor
Cisco
Product
Mds 9216
Cisco
Mds 9216
Vendor
Cisco
Product
Mds 9216a
Cisco
Mds 9216a
Vendor
Cisco
Product
Mds 9216i
Cisco
Mds 9216i
Vendor
Cisco
Product
Mds 9222i
Cisco
Mds 9222i
Vendor
Cisco
Product
Mds 9506
Cisco
Mds 9506
Vendor
Cisco
Product
Mds 9509
Cisco
Mds 9509
Vendor
Cisco
Product
Mds 9513
Cisco
Mds 9513
Vendor
Cisco
Product
Mds 9706
Cisco
Mds 9706
Vendor
Cisco
Product
Mds 9710
Cisco
Mds 9710
Vendor
Cisco
Product
Mds 9718
Cisco
Mds 9718
Vendor
Cisco
Product
Nexus 7000
Cisco
Nexus 7000
Vendor
Cisco
Product
Nexus 7700
Cisco
Nexus 7700
Vendor
Cisco
Product
Nx-os
Cisco
Nx-os
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
