Input validation error in Cisco FXOS and Cisco NX-OS - CVE-2019-1963

 

Input validation error in Cisco FXOS and Cisco NX-OS - CVE-2019-1963

Published: September 2, 2019


Vulnerability identifier: #VU20539
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1963
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of Abstract Syntax Notation One (ASN.1)-encoded variables in SNMP packets. A remote authenticated attacker can send a specially crafted SNMP packet to the SNMP daemon and cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition.

This vulnerability affects the following products if they have SNMP configured and they are running a vulnerable release of Cisco FXOS or NX-OS Software:

  • Firepower 4100 Series
  • Firepower 9300 Security Appliances
  • MDS 9000 Series Multilayer Switches
  • Nexus 1000 Virtual Edge for VMware vSphere
  • Nexus 1000V Switch for Microsoft Hyper-V
  • Nexus 1000V Switch for VMware vSphere
  • Nexus 3000 Series Switches
  • Nexus 3500 Platform Switches
  • Nexus 3600 Platform Switches
  • Nexus 5500 Platform Switches
  • Nexus 5600 Platform Switches
  • Nexus 6000 Series Switches
  • Nexus 7000 Series Switches
  • Nexus 7700 Series Switches
  • Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode
  • Nexus 9000 Series Switches in standalone NX-OS mode
  • Nexus 9500 R-Series Switching Platform
  • UCS 6200 Series Fabric Interconnects
  • UCS 6300 Series Fabric Interconnects
  • UCS 6400 Series Fabric Interconnects


Affected software

Cisco FXOS
Cisco NX-OS

How to mitigate CVE-2019-1963

Install updates from vendor's website.

Cisco FXOS - addressed in versions 2.2.2.91, 2.3.1.130, 2.4.1.222
Cisco NX-OS - addressed in versions 5.2.1 SV3.4.1a, 5.2.1 SV5.1.2, 6.2.22, 6.2.29, 7.0.3 I4.9 2, 7.0.3 I7.6, 7.1.5 N1.1b, 7.3.4 D1.1, 7.3.5 N1.1, 8.2.3, 8.3.2, 8.4.1, 9.2.3, 13.2.7k, 14.0.2c, 14.1.1i

External References

Related Security Bulletins