Executive Summary

Summary
TitleCisco Nexus 9000 Series ACI Mode Switch Software Link Layer Discovery Protocol Buffer Overflow Vulnerability
Informations
Namecisco-sa-20190731-nxos-boFirst vendor Publication2019-07-31
VendorCiscoLast vendor Modification2019-07-31
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:A/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score8.3Attack RangeAdjacent network
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score6.5AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges.

The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges.

Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJdQbtBXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczQQUP/1VobeEtedogbuxbwYO8Nscb3M65 QCgL4An1EKVXbBGbcNtc4wfsfeO33yT7QhPKCApdHmBVF6w8ZJYHN4gbQNUXPek7 nKBvFOtlmutvTju6UdBCNjgFuQFe9V0cZWJWjCAuUQN9S0O4bG7Y0pTqdPaZt85U yos/poUFPKWUIf91ZlctbTF1pxnzdfrYY/ybpSvOzbZGH2HwRa49XiSuCCPLq45x HwZS+04ROZjmcsRPhijlr5tW1Q2idC9kY45atsf1R2HtPXanFTktPqeMUEeG3Q55 zlTXnCSe36xdc6b5lfWQD1Fx3LY9yTfX2YXlGWNE6YHiqEGd6Q38ymAMMJfbieMb Sl2wEUJQOrEbHFVm74hTRhiLP7Ctt3BH8bF2Fco5MK76iKStv9GDv+IZf66JWQt7 1ulkye4TCvfREN/APc8LJRwAcmS8Q5ZUvFJfHRLjMjVOhWG5JWWEw9Np3lbLBx81 tl5W1URvow7jkQYOMM/5Wb2yM1PsxPL+bT7SU4adlIhVMNv0/uES/aqnKzMYYYch ZWMV7KgQxs8nkTGUQ9AEXS+yI68d2YkGJps9RsNGeiroptMpKVO3E3q14Rbx7BsE yR4unPzhbZO2jSG2SdS47oKqG2CmV3CYeNUkSD5WP2Nf3u0YCCqpPf1jyX3zkW72 EFWInRnO6t+FAQSk =kqnp END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

%idName
100 %CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Hardware1
Os312

Alert History

If you want to see full details history, please login or register.
0
1
2
DateInformations
2019-08-12 09:20:25
  • Multiple Updates
2019-08-01 00:22:04
  • Multiple Updates
2019-07-31 21:18:52
  • First insertion