Executive Summary
Summary | |
---|---|
Title | Cisco Nexus 9000 Series ACI Mode Switch Software Link Layer Discovery Protocol Buffer Overflow Vulnerability |
Informations | |||
---|---|---|---|
Name | cisco-sa-20190731-nxos-bo | First vendor Publication | 2019-07-31 |
Vendor | Cisco | Last vendor Modification | 2019-07-31 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:A/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 8.3 | Attack Range | Adjacent network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 6.5 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo"] BEGIN PGP SIGNATURE iQJ5BAEBAgBjBQJdQbtBXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczQQUP/1VobeEtedogbuxbwYO8Nscb3M65 QCgL4An1EKVXbBGbcNtc4wfsfeO33yT7QhPKCApdHmBVF6w8ZJYHN4gbQNUXPek7 nKBvFOtlmutvTju6UdBCNjgFuQFe9V0cZWJWjCAuUQN9S0O4bG7Y0pTqdPaZt85U yos/poUFPKWUIf91ZlctbTF1pxnzdfrYY/ybpSvOzbZGH2HwRa49XiSuCCPLq45x HwZS+04ROZjmcsRPhijlr5tW1Q2idC9kY45atsf1R2HtPXanFTktPqeMUEeG3Q55 zlTXnCSe36xdc6b5lfWQD1Fx3LY9yTfX2YXlGWNE6YHiqEGd6Q38ymAMMJfbieMb Sl2wEUJQOrEbHFVm74hTRhiLP7Ctt3BH8bF2Fco5MK76iKStv9GDv+IZf66JWQt7 1ulkye4TCvfREN/APc8LJRwAcmS8Q5ZUvFJfHRLjMjVOhWG5JWWEw9Np3lbLBx81 tl5W1URvow7jkQYOMM/5Wb2yM1PsxPL+bT7SU4adlIhVMNv0/uES/aqnKzMYYYch ZWMV7KgQxs8nkTGUQ9AEXS+yI68d2YkGJps9RsNGeiroptMpKVO3E3q14Rbx7BsE yR4unPzhbZO2jSG2SdS47oKqG2CmV3CYeNUkSD5WP2Nf3u0YCCqpPf1jyX3zkW72 EFWInRnO6t+FAQSk =kqnp END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com |
Original Source
Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...) |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Alert History
Date | Informations |
---|---|
2019-08-12 09:20:25 |
|
2019-08-01 00:22:04 |
|
2019-07-31 21:18:52 |
|