Buffer over-read in Cisco NX-OS - CVE-2018-0310
Published: June 20, 2018 / Updated: June 25, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The vulnerability exists in the Cisco Fabric Services component due to buffer over-read when insufficient validation of header values in Cisco Fabric Services packets. A remote unauthenticated attacker can send a specially crafted Cisco Fabric Services packet, trigger memory corruption and obtain sensitive information from memory or cause the service to crash.
Affected software
Cisco FXOS
UCS 6300 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6100 Series Fabric Interconnects