Vulnerability CVE-2019-1616


Published: 2019-03-11

Description:
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25), 8.1(1b), 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5) Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22) and 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5). UCS 6200, 6300, and 6400 Fabric Interconnects are affected running software versions prior to 3.2(3j) and 4.0(2a).

Vendor: Cisco
Product: Nx-os 
Version:
8.3(0)cv(0.345)
8.3(0)cv(0.342)
8.1(1)s5
8.1(1)
8.1(0.59)s0
8.1(0.2)s0
8.1(0.112)s0
8.0(1)s2
7.3(2)n1(0.395)
7.3(2)n1(0.296)
7.3(0)zn(0.9)
7.3(0)zn(0.83)
7.3(0)zn(0.81)
7.3(0)n1(1)
7.2(1)n1(1)
7.2(0)zz(99.3)
7.2(0)zz(99.1)
7.2(0)n1(1)
7.2(0)n1(0.1)
7.0\(3\)i4
7.0(8)n1(1)
7.0(7)n1(1)
7.0(6)n1(1)
7.0(5)n1(1a)
7.0(5)n1(1)
7.0(4)n1(1)
7.0(3)n1(1)
7.0(3)i7
7.0(3)i2(0.373)
7.0(3)i1(2)
7.0(3)i1(1b)
7.0(3)i1(1a)
7.0(3)
7.0(2)n1(1)
7.0(1)n1(3)
7.0(1)n1(1)
7.0(0)n1(1)
6.2(8b)
6.2(8a)
6.2(8)
6.2(7)
6.2(6b)
6.2(6)
6.2(5a)
6.2(5)
6.2(3n)
6.2(3)
6.2(2a)
6.2(2)
6.2(1n)
6.2(14)s1
6.2(12)
6.2(11b)
6.2(10)
6.2(1)
6.1(5)
6.1(4a)
6.1(4)
6.1(3)
6.1(2)i3(4)
6.1(2)i3(3.78)
6.1(2)i3(3)
6.1(2)i3(2)
6.1(2)i3(1)
6.1(2)i2(3)
6.1(2)i2(2b)
6.1(2)i2(2a)
6.1(2)i2(2)
6.1(2)
6.1(1)
6.1
6.0\(2\)a8
6.0(4)
6.0(3)
6.0(2)u6(8)
6.0(2)u6(7)
6.0(2)u6(6)
6.0(2)u6(5)
6.0(2)u6(4)
6.0(2)u6(3)
6.0(2)u6(2)
6.0(2)u6(1)
6.0(2)u5(4)
6.0(2)u5(3)
6.0(2)u5(2)
6.0(2)u5(1.41)
6.0(2)u5(1)
6.0(2)u4(3)
6.0(2)u4(2)
6.0(2)u4(1)
6.0(2)u3(5)
6.0(2)u3(4)
6.0(2)u3(3)
6.0(2)u3(2)
6.0(2)u3(1)
6.0(2)u2(6)
6.0(2)u2(5)
6.0(2)u2(4)
6.0(2)u2(3)
6.0(2)u2(2)
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.securityfocus.com/bid/107395
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-fabric-dos

Related CVE
CVE-2019-1711
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling o...
CVE-2018-7340
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing...
CVE-2019-1786
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected ...
CVE-2019-1762
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed...
CVE-2019-1761
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to i...
CVE-2019-1760
A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload. The vulnerability is due to the processing of malformed smart probe packets. An ...
CVE-2019-1759
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management i...
CVE-2019-1758
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packets are hand...

Copyright 2019, cxsecurity.com

 

Back to Top