Null pointer dereference in Cisco NX-OS - CVE-2018-0305
Published: June 20, 2018 / Updated: June 25, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the Cisco Fabric Services component due to insufficient validation of Cisco Fabric Services packets. A remote attacker can send a specially crafted Cisco Fabric Services packet, trigger a NULL pointer dereference and cause the service to crash.
Affected software
Cisco FXOS
UCS 6300 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6100 Series Fabric Interconnects