PT-2013-2949 · Cisco · Nexus 3000+4
Published
2013-04-24
·
Updated
2018-10-30
·
CVE-2013-1181
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS on Nexus 5500 devices versions 4.x through 5.x before 5.0(3)N2(2)
Cisco NX-OS on Nexus 3000 devices versions 5.x before 5.0(3)U3(2)
Cisco Unified Computing System (UCS) 6200 devices versions before 2.0(1w)
Description
The issue allows remote attackers to cause a denial of service by sending a jumbo packet to the management interface. This can result in a device reload. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Cisco NX-OS on Nexus 5500 devices versions 4.x through 5.x before 5.0(3)N2(2), update to version 5.0(3)N2(2) or later.
For Cisco NX-OS on Nexus 3000 devices versions 5.x before 5.0(3)U3(2), update to version 5.0(3)U3(2) or later.
For Cisco Unified Computing System (UCS) 6200 devices versions before 2.0(1w), update to version 2.0(1w) or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus
Cisco Unified Computing System (Ucs) 6200
Nexus 3000
Nexus 5500