Security News > 2020 > October > Chinese Hackers Target Cisco Discovery Protocol Vulnerability

Chinese Hackers Target Cisco Discovery Protocol Vulnerability
2020-10-21 10:04

Chinese state-sponsored hackers are targeting a Cisco Discovery Protocol vulnerability that was disclosed earlier this year, the networking giant and the U.S. National Security Agency revealed on Tuesday.

The list includes several vulnerabilities that were not known to have been targeted, including CVE-2020-3118, which impacts Cisco products.

CVE-2020-3118 is one of the five vulnerabilities in the Cisco Discovery Protocol implementation of IOS XR software that were disclosed in February by IoT security firm Armis.

Just as the NSA issued its warning on the vulnerabilities targeted by Chinese hackers, Cisco updated its advisory to inform customers that it received reports earlier this month of attackers attempting to exploit CVE-2020-3118 in the wild.

While it's unclear which Chinese threat actor has targeted the flaw, the group tracked as APT41 is known to have exploited Cisco product vulnerabilities in its attacks.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/vAzTb6GVzYw/chinese-hackers-target-cisco-discovery-protocol-vulnerability

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2020-3118 Out-of-bounds Write vulnerability in Cisco IOS XR
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device.
low complexity
cisco CWE-787
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 2046 21 1773 1669 288 3751
Protocol 12 0 1 15 1 17