CVE-2020-3119: Cisco NX-OS
High severity, CVSS 8.8. EPSS: 4.8% chance of exploitation in the next 30 days.
A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected products
- Cisco NX-OS: from 7.0\(3\)f2, before 9.3\(2\) (fixed in 9.3\(2\)); from 7.0\(3\)i, before 7.0\(3\)i7\(8\) (fixed in 7.0\(3\)i7\(8\)); from 7.1, before 7.3\(6\)n1\(1\) (fixed in 7.3\(6\)n1\(1\)); before 9.3\(2\) (fixed in 9.3\(2\)); from 14.0, before 14.2\(1j\) (fixed in 14.2\(1j\))
- Cisco Ucs Manager: before 3.2\(3m\) (fixed in 3.2\(3m\)); from 4.0, before 4.0\(4f\) (fixed in 4.0\(4f\))
Published 2020-02-05. Last modified 2026-06-17.