Improper input validation in Cisco Nexus 9000 Series Switches - CVE-2018-0372

 

Improper input validation in Cisco Nexus 9000 Series Switches - CVE-2018-0372

Published: July 18, 2018 / Updated: July 23, 2018


Vulnerability identifier: #VU13971
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0372
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode due to improper memory management when DHCPv6 packets are received on an interface of the targeted device. A remote attacker can send a high number of malicious DHCPv6 packets, cause the system to run low on memory, and trigger an eventual reboot of an affected device.


Affected software

Cisco Nexus 9000 Series Switches

How to mitigate CVE-2018-0372

Update to version 13.0(2k).

Cisco Nexus 9000 Series Switches - update to 13.0.2k

External References

Related Security Bulletins