PT-2019-2152 · Cisco · Cisco Nx-Os+2
CVE-2019-1858
·
Publicado
2019-05-15
·
Atualizado
2023-04-20
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco FXOS Software (affected versions not specified)
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, leading to an affected device restarting unexpectedly. The issue is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this by sending multiple crafted SNMP packets to an affected device, causing the SNMP application to leak system memory over time. This could result in the SNMP application restarting multiple times, leading to a system-level restart and a denial of service (DoS) condition.
Recommendations
For Cisco FXOS Software, update to a version that includes the fix for this issue.
For Cisco NX-OS Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SNMP application to minimize the risk of exploitation.
Correção
DoS
Improper Handling of Exceptional Conditions
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Fxos
Cisco Nx-Os
Cisco Nexus