Improper input validation in Cisco Nexus 4000 Series Switches - CVE-2018-0299

 

Improper input validation in Cisco Nexus 4000 Series Switches - CVE-2018-0299

Published: June 20, 2018 / Updated: June 21, 2018


Vulnerability identifier: #VU13414
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0299
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The vulnerability exists in the Simple Network Management Protocol (SNMP) feature of the Cisco Nexus 4000 Series Switch due to incomplete validation of an SNMP poll request for a specific MIB. A remote attacker can send a specific SNMP poll request and cause the device to reload.


Affected software

Cisco Nexus 4000 Series Switches

How to mitigate CVE-2018-0299

The vulnerability is addressed in the versions 4.0(0.58), 4.0(0.56), 4.1(2)E1(1s).

Cisco Nexus 4000 Series Switches - addressed in versions 4.0.0.56, 4.0.0.58, 4.1.2 E1.1s

External References

Related Security Bulletins