CVE-2020-3120: Cisco Firepower Extensible Operating System
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).
Affected products
- Cisco Firepower Extensible Operating System: up to and including 2.3.1.173; from 2.6, before 2.6.1.187 (fixed in 2.6.1.187); from 2.7, before 2.7.1.106 (fixed in 2.7.1.106)
- Cisco Fxos: version 2.4 only
- Cisco IOS XR: version 5.2.5 only; version 6.4.2 only; version 6.5.3 only; version 6.6.25 only; version 7.0.1 only
- Cisco NX-OS: from 5.2, before 6.2\(29\) (fixed in 6.2\(29\)); from 7.3, before 8.4\(1a\) (fixed in 8.4\(1a\)); from 5.2, before 5.2\(1\)sv5\(1.3\) (fixed in 5.2\(1\)sv5\(1.3\)); up to and including 5.2; before 5.2\(1\)sv3\(4.1b\) (fixed in 5.2\(1\)sv3\(4.1b\)); from 7.0\(3\)f2, before 9.3\(2\) (fixed in 9.3\(2\)); …
- Cisco Ucs Manager: before 3.2\(3m\) (fixed in 3.2\(3m\)); from 4.0, before 4.0\(4g\) (fixed in 4.0\(4g\))
Published 2020-02-05. Last modified 2026-06-17.