VDB

CVE-2020-3506

CVE-2020-3506 PUBLISHED CVSS 8.800000190734863 HIGH

Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process a Cisco Discovery Protocol packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to the targeted IP camera. A successful exploit could allow the attacker to execute code on the affected IP camera or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

EPSS 0.12% · 30.0th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
30.0th percentile

Affected Products

VendorProductVersions
cisco8000p_ip_camera_firmware1.0.9-1
cisco8930_speed_dome_ip_camera_firmware1.0.9-1
cisco8630_ip_camera_firmware1.0.9-1
CiscoCisco Video Surveillance 8000 Series IP Cameras*
cisco8070_ip_camera_firmware1.0.9-1
cisco8620_ip_camera_firmware1.0.9-1
cisco8030_ip_camera_firmware1.0.9-1
cisco8400_ip_camera_firmware1.0.9-1
cisco8020_ip_camera_firmware1.0.9-1

Timeline

  • Aug 19, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›