PT-2013-2973 · Vmware+1 · Vmware Esxi+2

Published

2013-05-29

·

Updated

2013-05-30

·

CVE-2013-1210

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Nexus 1000V Virtual Ethernet Module (VEM) kernel driver for VMware ESXi (affected versions not specified)
Description A denial of service issue exists due to insufficient validation of STUN protocol packets, resulting in an out of bound array index access and a crash of the ESXi hypervisor, leading to a purple screen of death. This can be exploited by sending specially crafted STUN packets to a vulnerable VEM when STUN protocol debugging is enabled. The issue requires access to a trusted, internal network to send the crafted packets, limiting the possibility of a successful exploit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1210

Affected Products

Cisco Nexus
Cisco Nexus 1000V Virtual Ethernet Module (Vem) Kernel Driver
Vmware Esxi