PT-2019-1574 · Cisco · Cisco Nx-Os+1

Publicado

2019-03-06

·

Atualizado

2019-10-09

·

CVE-2019-1617

CVSS v3.1

7.4

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software versions prior to 7.0(3)I7(5) and 9.2(2)
Description A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker could exploit this vulnerability by sending a stream of FCoE frames from an adjacent host to an affected device, causing packet amplification to occur, resulting in the saturation of interfaces and a DoS condition.
Recommendations For versions prior to 7.0(3)I7(5), update to version 7.0(3)I7(5) or later. For versions prior to 9.2(2), update to version 9.2(2) or later. As a temporary workaround, consider disabling the fcoe-npv feature until a patch is available. Restrict access to the affected device to minimize the risk of exploitation.

Exploit

Correção

DoS

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01105
CVE-2019-1617

Produtos afetados

Cisco Nx-Os
Cisco Nexus