SB2016100601 - Remote code execution in Cisco Nexus
Published: October 6, 2016
Security Bulletin ID
SB2016100601
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Remote code execution (CVE-ID: CVE-2016-1453)
The vulnerability allows a remote unauthenticated user to cause the target system reload or execute arbitrary code.The weakness is due to a buffer overflow caused by insufficient input validation of the size of OTV packet header parameters. By sending a specially crafted OTV UDP packet to the OTV interface attackers can cause OTV process reload or arbitrary code execution and obtain full control of the system.
Successful exploitation of the vulnerability results in arbitrary code execution and complete access to the vulnerable system.
Remediation
Install update from vendor's website.