PT-2019-1561 · Cisco · Ucs 6200/6300 Series Fabric Interconnect+3

Publicado

2019-03-06

·

Atualizado

2020-10-08

·

CVE-2019-1599

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software versions prior to 5.2(1)SM3(2.1) Cisco NX-OS Software versions prior to 5.2(1)SV3(4.1a) Cisco NX-OS Software versions prior to 7.0(3)I7(6) Cisco NX-OS Software versions prior to 7.1(5)N1(1b) Cisco NX-OS Software versions prior to 7.3(5)N1(1) Cisco NX-OS Software versions prior to 9.2(2) Cisco NX-OS Software versions prior to 6.0(2)A8(11) Cisco NX-OS Software versions prior to 6.2(22) Cisco NX-OS Software versions prior to 7.0(3)F3(5) UCS 6200 and 6300 Series Fabric Interconnect versions prior to 3.2(3j) UCS 6200 and 6300 Series Fabric Interconnect versions prior to 4.0(2a) UCS 6400 Series Fabric Interconnect versions prior to 4.0(2a)
Description A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could exploit this vulnerability by sending crafted TCP streams to an affected device in a sustained way. A successful exploit could cause the network stack of an affected device to run out of available buffers, impairing operations of control plane and management plane protocols, resulting in a DoS condition. This vulnerability can be triggered only by traffic that is destined to an affected device and cannot be exploited using traffic that transits an affected device.
Recommendations For Cisco NX-OS Software versions prior to 5.2(1)SM3(2.1), update to version 5.2(1)SM3(2.1) or later. For Cisco NX-OS Software versions prior to 5.2(1)SV3(4.1a), update to version 5.2(1)SV3(4.1a) or later. For Cisco NX-OS Software versions prior to 7.0(3)I7(6), update to version 7.0(3)I7(6) or later. For Cisco NX-OS Software versions prior to 7.1(5)N1(1b), update to version 7.1(5)N1(1b) or later. For Cisco NX-OS Software versions prior to 7.3(5)N1(1), update to version 7.3(5)N1(1) or later. For Cisco NX-OS Software versions prior to 9.2(2), update to version 9.2(2) or later. For Cisco NX-OS Software versions prior to 6.0(2)A8(11), update to version 6.0(2)A8(11) or later. For Cisco NX-OS Software versions prior to 6.2(22), update to version 6.2(22) or later. For Cisco NX-OS Software versions prior to 7.0(3)F3(5), update to version 7.0(3)F3(5) or later. For UCS 6200 and 6300 Series Fabric Interconnect versions prior to 3.2(3j), update to version 3.2(3j) or later. For UCS 6200 and 6300 Series Fabric Interconnect versions prior to 4.0(2a), update to version 4.0(2a) or later. For UCS 6400 Series Fabric Interconnect versions prior to 4.0(2a), update to version 4.0(2a) or later.

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01092
CVE-2019-1599

Produtos afetados

Cisco Nx-Os
Cisco Nexus
Ucs 6200/6300 Series Fabric Interconnect
Ucs 6400 Series Fabric Interconnect