Buffer overflow in Cisco FXOS - CVE-2018-0298

 

Buffer overflow in Cisco FXOS - CVE-2018-0298

Published: June 20, 2018 / Updated: June 25, 2018


Vulnerability identifier: #VU13449
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0298
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in the web UI due to buffer overflow when handling malicious input. A remote attacker can send a malicious HTTP or HTTPS packet directed to the physical management interface and cause the process to crash and possibly reload the device.


Affected software

Cisco FXOS
UCS 6300 Series Fabric Interconnects
UCS 6200 Series Fabric Interconnects
UCS 6100 Series Fabric Interconnects

How to mitigate CVE-2018-0298

Install update from vendor's website.


External References

Related Security Bulletins