Description
A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of Border Gateway Protocol (BGP) update messages that contain crafted EVPN attributes. An attacker could exploit this vulnerability by sending BGP update messages with specific, malformed attributes to an affected device. A successful exploit could allow the attacker to cause an affected device to crash, resulting in a DoS condition.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24750 | A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of Border Gateway Protocol (BGP) update messages that contain crafted EVPN attributes. An attacker could exploit this vulnerability by sending BGP update messages with specific, malformed attributes to an affected device. A successful exploit could allow the attacker to cause an affected device to crash, resulting in a DoS condition. |
References
History
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
1100 Integrated Services Router
Subscribe
1101 Integrated Services Router
Subscribe
1109 Integrated Services Router
Subscribe
1111x Integrated Services Router
Subscribe
111x Integrated Services Router
Subscribe
1120 Integrated Services Router
Subscribe
1160 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451-x Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-x
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-x
Subscribe
Asr 1004
Subscribe
Asr 1006
Subscribe
Asr 1006-x
Subscribe
Asr 1009-x
Subscribe
Asr 1013
Subscribe
Cloud Services Router 1000v
Subscribe
Ios
Subscribe
Ios Xe
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-13T17:58:10.602Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2020-3479
Updated: 2024-08-04T07:37:54.300Z
Status : Modified
Published: 2020-09-24T18:15:20.010
Modified: 2024-11-21T05:31:09.220
Link: CVE-2020-3479
No data.
OpenCVE Enrichment
No data.
EUVD