Vulnerability CVE-2019-1616


Published: 2019-03-11

Description:
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25), 8.1(1b), 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5) Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22) and 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5). UCS 6200, 6300, and 6400 Fabric Interconnects are affected running software versions prior to 3.2(3j) and 4.0(2a).

Vendor: Cisco
Product: Nx-os 
Version:
8.3(0)cv(0.345)
8.3(0)cv(0.342)
8.1(1)s5
8.1(1)
8.1(0.59)s0
8.1(0.2)s0
8.1(0.112)s0
8.0(1)s2
7.3(2)n1(0.395)
7.3(2)n1(0.296)
7.3(0)zn(0.9)
7.3(0)zn(0.83)
7.3(0)zn(0.81)
7.3(0)n1(1)
7.2(1)n1(1)
7.2(0)zz(99.3)
7.2(0)zz(99.1)
7.2(0)n1(1)
7.2(0)n1(0.1)
7.0\(3\)i4
7.0(8)n1(1)
7.0(7)n1(1)
7.0(6)n1(1)
7.0(5)n1(1a)
7.0(5)n1(1)
7.0(4)n1(1)
7.0(3)n1(1)
7.0(3)i7
7.0(3)i2(0.373)
7.0(3)i1(2)
7.0(3)i1(1b)
7.0(3)i1(1a)
7.0(3)
7.0(2)n1(1)
7.0(1)n1(3)
7.0(1)n1(1)
7.0(0)n1(1)
6.2(8b)
6.2(8a)
6.2(8)
6.2(7)
6.2(6b)
6.2(6)
6.2(5a)
6.2(5)
6.2(3n)
6.2(3)
6.2(2a)
6.2(2)
6.2(1n)
6.2(14)s1
6.2(12)
6.2(11b)
6.2(10)
6.2(1)
6.1(5)
6.1(4a)
6.1(4)
6.1(3)
6.1(2)i3(4)
6.1(2)i3(3.78)
6.1(2)i3(3)
6.1(2)i3(2)
6.1(2)i3(1)
6.1(2)i2(3)
6.1(2)i2(2b)
6.1(2)i2(2a)
6.1(2)i2(2)
6.1(2)
6.1(1)
6.1
6.0\(2\)a8
6.0(4)
6.0(3)
6.0(2)u6(8)
6.0(2)u6(7)
6.0(2)u6(6)
6.0(2)u6(5)
6.0(2)u6(4)
6.0(2)u6(3)
6.0(2)u6(2)
6.0(2)u6(1)
6.0(2)u5(4)
6.0(2)u5(3)
6.0(2)u5(2)
6.0(2)u5(1.41)
6.0(2)u5(1)
6.0(2)u4(3)
6.0(2)u4(2)
6.0(2)u4(1)
6.0(2)u3(5)
6.0(2)u3(4)
6.0(2)u3(3)
6.0(2)u3(2)
6.0(2)u3(1)
6.0(2)u2(6)
6.0(2)u2(5)
6.0(2)u2(4)
6.0(2)u2(3)
6.0(2)u2(2)
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.securityfocus.com/bid/107395
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-fabric-dos

Related CVE
CVE-2019-1873
A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability...
CVE-2019-1933
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input va...
CVE-2019-1932
A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamica...
CVE-2019-1931
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-ba...
CVE-2019-1930
Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-ba...
CVE-2019-1922
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient ...
CVE-2019-1921
A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper inp...
CVE-2019-1911
A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell com...

Copyright 2019, cxsecurity.com

 

Back to Top