5.3
CVE-2020-3170
- EPSS 0.4%
- Published 26.02.2020 17:15:13
- Last modified 21.11.2024 05:30:28
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version < 8.4\(1\)
Cisco ≫ Mds 9132t Version-
Cisco ≫ Mds 9148s Version-
Cisco ≫ Mds 9148t Version-
Cisco ≫ Mds 9216 Version-
Cisco ≫ Mds 9216a Version-
Cisco ≫ Mds 9216i Version-
Cisco ≫ Mds 9222i Version-
Cisco ≫ Mds 9506 Version-
Cisco ≫ Mds 9509 Version-
Cisco ≫ Mds 9513 Version-
Cisco ≫ Mds 9706 Version-
Cisco ≫ Mds 9710 Version-
Cisco ≫ Mds 9718 Version-
Cisco ≫ Mds 9148s Version-
Cisco ≫ Mds 9148t Version-
Cisco ≫ Mds 9216 Version-
Cisco ≫ Mds 9216a Version-
Cisco ≫ Mds 9216i Version-
Cisco ≫ Mds 9222i Version-
Cisco ≫ Mds 9506 Version-
Cisco ≫ Mds 9509 Version-
Cisco ≫ Mds 9513 Version-
Cisco ≫ Mds 9706 Version-
Cisco ≫ Mds 9710 Version-
Cisco ≫ Mds 9718 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.4% | 0.598 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
psirt@cisco.com | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.