Vulnerability CVE-2019-1858


Published: 2019-05-15   Modified: 2019-05-16

Description:
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this vulnerability by sending multiple crafted SNMP packets to an affected device. A successful exploit could allow the attacker to cause the SNMP application to leak system memory because of an improperly handled error condition during packet processing. Over time, this memory leak could cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition.

Type:

CWE-20

(Improper Input Validation)

Vendor: Cisco
Product: Nx-os 
Version:
9.1(1)sv1(3.1.8)
8.3(1)
8.3(0)cv(0.345)
8.3(0)cv(0.342)
8.3
8.2(3)
8.2(2)
8.2
8.1(1b)
8.1(1)s5
8.1(1)
8.1(0.59)s0
8.1(0.2)s0
8.1(0.112)s0
8.1
8.0(1)s2
8.0
7.3(2)n1(0.395)
7.3(2)n1(0.296)
7.3(0)zn(0.9)
7.3(0)zn(0.83)
7.3(0)zn(0.81)
7.3(0)n1(1)
7.3
7.2(1)n1(1)
7.2(0)zz(99.3)
7.2(0)zz(99.1)
7.2(0)n1(1)
7.2(0)n1(0.1)
7.1(4)n1(1)
7.1(3)n1(3.12)
7.1(3)n1(2.1)
7.1(3)n1(2)
7.1(3)n1(1)
7.1(2)n1(1)
7.1(1)n1(1)
7.1(0)n1(1b)
7.1(0)n1(1a)
7.0(8)n1(1)
7.0(7)n1(1)
7.0(6)n1(1)
7.0(5)n1(1a)
7.0(5)n1(1)
7.0(4)n1(1)
7.0(3)n1(1)
7.0(3)i7
7.0(3)i2(0.373)
7.0(3)i1(2)
7.0(3)i1(1b)
7.0(3)i1(1a)
7.0(3)
7.0(2)n1(1)
7.0(1)n1(3)
7.0(1)n1(1)
7.0(0)n1(1)
6.2(8b)
6.2(8a)
6.2(8)
6.2(7)
6.2(6b)
6.2(6)
6.2(5a)
6.2(5)
6.2(3n)
6.2(3)
6.2(2a)
6.2(2)
6.2(1n)
6.2(14)s1
6.2(12)
6.2(11b)
6.2(10)
6.2(1)
6.1(5)
6.1(4a)
6.1(4)
6.1(3)
6.1(2)i3(4)
6.1(2)i3(3.78)
6.1(2)i3(3)
6.1(2)i3(2)
6.1(2)i3(1)
6.1(2)i2(3)
6.1(2)i2(2b)
6.1(2)i2(2a)
6.1(2)i2(2)
6.1(2)
6.1(1)
6.1
6.0(4)
6.0(3)
6.0(2)u6(8)
6.0(2)u6(7)
6.0(2)u6(6)
6.0(2)u6(5)
6.0(2)u6(4)
6.0(2)u6(3)
6.0(2)u6(2)
6.0(2)u6(1)
6.0(2)u5(4)
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.securityfocus.com/bid/108358
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-snmp-dos

Related CVE
CVE-2019-1915
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco U...
CVE-2019-15272
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerab...
CVE-2019-15259
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that ar...
CVE-2019-15256
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an aff...
CVE-2019-12716
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...
CVE-2019-12715
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attac...
CVE-2019-12713
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected so...
CVE-2019-12712
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected so...

Copyright 2019, cxsecurity.com

 

Back to Top