Improper input validation in Cisco Nexus 9000 Series Switches - CVE-2018-0372
Published: July 18, 2018 / Updated: July 23, 2018
Cisco Nexus 9000 Series Switches
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode due to improper memory management when DHCPv6 packets are received on an interface of the targeted device. A remote attacker can send a high number of malicious DHCPv6 packets, cause the system to run low on memory, and trigger an eventual reboot of an affected device.