CVE-2020-3172: Cisco Firepower Extensible Operating System

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to a Layer 2-adjacent affected device. A successful exploit could allow the attacker to cause a buffer overflow that could allow the attacker to execute arbitrary code as root or cause a DoS condition on the affected device. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Note: This vulnerability is different from the following Cisco FXOS and NX-OS Software Cisco Discovery Protocol vulnerabilities that Cisco announced on Feb. 5, 2020: Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability and Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability.

Affected products

  • Cisco Firepower Extensible Operating System: before 2.6.1.187 (fixed in 2.6.1.187); from 2.7, before 2.7.1.106 (fixed in 2.7.1.106)
  • Cisco NX-OS: affected versions not specified; version 5.2(1)sv5(1.2) only; version 7.3(5)n1(1) only; version 7.3(0)d1(0.140) only; version 7.3(0)d1(0.146) only; version 7.0(3)i3(0.191) only; …
  • Cisco Ucs Manager: before 3.2\(3n\) (fixed in 3.2\(3n\)); from 4.0, before 4.0\(4g\) (fixed in 4.0\(4g\))

Published 2020-02-26. Last modified 2026-06-17.