PT-2013-2949 · Cisco · Nexus 3000+4

Published

2013-04-24

·

Updated

2018-10-30

·

CVE-2013-1181

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS on Nexus 5500 devices versions 4.x through 5.x before 5.0(3)N2(2) Cisco NX-OS on Nexus 3000 devices versions 5.x before 5.0(3)U3(2) Cisco Unified Computing System (UCS) 6200 devices versions before 2.0(1w)
Description The issue allows remote attackers to cause a denial of service by sending a jumbo packet to the management interface. This can result in a device reload. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Cisco NX-OS on Nexus 5500 devices versions 4.x through 5.x before 5.0(3)N2(2), update to version 5.0(3)N2(2) or later. For Cisco NX-OS on Nexus 3000 devices versions 5.x before 5.0(3)U3(2), update to version 5.0(3)U3(2) or later. For Cisco Unified Computing System (UCS) 6200 devices versions before 2.0(1w), update to version 2.0(1w) or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1181

Affected Products

Cisco Nx-Os
Cisco Nexus
Cisco Unified Computing System (Ucs) 6200
Nexus 3000
Nexus 5500