#VU13446 Buffer over-read in Cisco NX-OS - CVE-2018-0310
Published: June 20, 2018 / Updated: June 25, 2018
Cisco NX-OS
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The vulnerability exists in the Cisco Fabric Services component due to buffer over-read when insufficient validation of header values in Cisco Fabric Services packets. A remote unauthenticated attacker can send a specially crafted Cisco Fabric Services packet, trigger memory corruption and obtain sensitive information from memory or cause the service to crash.