CDPwn vulnerabilities open millions of Cisco enterprise devices to attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3110 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to the targeted IP Camera. A successful exploit could allow the attacker to expose the affected IP Camera for remote code execution or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). This vulnerability is fixed in Video Surveillance 8000 Series IP Camera Firmware Release 1.0.7 and later. NVD description · AI analysis pending | 8.8 | 6% |
| — | ||
| CVE-2020-3111 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2020-3118 | Format String Vulnerability in Cisco IOS XR Discovery Protocol Allows Adjacent RCE CVE-2020-3118 is a format string vulnerability (CWE-134) in the Cisco Discovery Protocol (CDP) implementation of Cisco IOS XR Software, caused by improper validation of string input from certain fields in CDP messages. An unauthenticated attacker who is Layer 2 adjacent (on the same broadcast domain) can trigger it by sending a malicious CDP packet to an affected device, causing a stack overflow (CWE-787). A successful exploit allows the attacker to execute arbitrary code with administrative privileges on the device, or alternatively to cause a device reload (denial of service). Any organization running Cisco IOS XR — typically service-provider and large-enterprise core, edge, and aggregation routers — is affected whenever CDP is enabled on interfaces reachable by an attacker at Layer 2. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, with no public PoC identified and an EPSS estimate of 11.7% (96th percentile) for exploitation within 30 days. Do: Apply updates to affected Cisco IOS XR devices per Cisco's advisory, as required by the CISA KEV catalog. As interim mitigation, disable Cisco Discovery Protocol on interfaces connected to untrusted Layer 2 segments or restrict broadcast-domain access to trusted devices. Prioritize IOS XR devices where untrusted users, partners, or shared infrastructure exist on the same VLAN or broadcast domain, since exploitation requires only L2 adjacency. | 8.8 | 12% | KEV |
| mass≈100,000+ IOS XR-based routers deployed globally, all potentially exposed where CDP is enabled | |
| CVE-2020-3119 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary c A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 8.8 | 5% |
| — | ||
| CVE-2020-3120 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthent A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 6.5 | 2% |
| — |
Full article629 words · extracted from helpnetsecurity.com · click to collapse
If you have Cisco equipment in your enterprise network – and chances are good that you have – you should check immediately which feature the newly revealed CDPwn vulnerabilities in Cisco’ proprietary device discovery protocol and implement patches as soon as possible.

The CDPwn vulnerabilities
Discovered by Armis researchers and responsibly disclosed to Cisco last year, the five “CDPwn” flaws – CVE-2020-3110, CVE-2020-3111, CVE-2020-3118, CVE-2020-3119 and CVE-2020-3120 – could be exploited to cause denial of service and/or remote code execution.
“Different models of devices that run Cisco FXOS Software, Cisco IP Camera Firmware, Cisco IP Phone Firmware, Cisco NX-OS Software, Cisco IOS-XR, and Cisco UCS Fabric Interconnects are affected by one or more of these vulnerabilities,” a Cisco spokesman told Help Net Security.
Not affected: routers and switches that run Cisco IOS and Cisco IOS-XE Software, and firewalls such as the Cisco ASA, Cisco Firepower 1000 Series, and Cisco Firepower 2100 Series. (Though CVE-2020-3120 affects the Firepower 4100 Series and Firepower 9300 Security Appliances).
All of the flaws affect the Cisco Discovery Protocol – a Layer 2 protocol that runs on Cisco devices and facilitates their management by discovering them, determining how they are configured, and allowing systems using different network-layer protocols to learn about each other.
“A well-known security best practice is to disable Cisco Discovery Protocol on all interfaces that are connected to untrusted networks. Each security advisory provides detailed information on how to determine if Cisco Discovery Protocol is enabled in your device and how to disable it, if applicable,” the Cisco spokesman pointed out.
“For those products that must run CDP for certain functionality, customers are encouraged to follow best practices on network segmentation to avoid untrusted devices from sending CDP packets or ultimately upgrade those devices with the available software fixes.”
Needless to say, fixes should be prioritized over CDP disablement.
Exploitation potential
First things first: Cisco PSIRT is not aware of any malicious use of any of the CDPwn vulnerabilities.
Also: These vulnerabilities cannot be exploited from the Internet or from a different broadcast domain/subnet – the attacker must be in the same broadcast domain or subnet as the affected device (“Layer-2” adjacent) to exploit the flaws. That means that the attacker has to first gain a foothold in the target network.

But, once that’s achieved, he or she can use the CDP vulnerabilities to:
- Break network segmentation
- Exfiltrate that from devices like IP phones and cameras and eavesdrop on voice and video data/calls and video feeds from them
- Steal sensitive corporate data flowing through the corporate network’s switches and routers
- Compromise device communications by leveraging MitM attacks to intercept and alter traffic on the corporate switch
“CDP is a protocol that is based on multicast ethernet packets that are sent throughout the network. An attacker that is connected to an affected switch, for example, can simply send a maliciously crafted CDP packet, which will trigger the vulnerability and can lead to remote code execution. Unfortunately, the discovered RCE vulnerabilities are all easily exploitable, being either stack or heap overflows, with minimal mitigations in place to prevent them turning into functional exploits,” Ben Seri, VP of Research at Armis, told Help Net Security.
As Armis pointed out, 95%+ Fortune 500 companies use Cisco Collaboration solutions, and large numbers of these devices end up in places that attackers find extremely valuable: trading floors, boardrooms, the CEO’s conference room, and so on.
“While enterprises will often use network segmentation as a means to isolate these devices from other parts of the network, CDPwn could be used to break through those boundaries to allow for unauthorized access and compromise,” they added.
More information about the flaws, fixes and mitigations can be found on Armis’s site, Cisco’s advisories and this blog post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/02/05/cdpwn-vulnerabilities/