PT-2013-2973 · Vmware+1 · Vmware Esxi+2
Published
2013-05-29
·
Updated
2013-05-30
·
CVE-2013-1210
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 1000V Virtual Ethernet Module (VEM) kernel driver for VMware ESXi (affected versions not specified)
Description
A denial of service issue exists due to insufficient validation of STUN protocol packets, resulting in an out of bound array index access and a crash of the ESXi hypervisor, leading to a purple screen of death. This can be exploited by sending specially crafted STUN packets to a vulnerable VEM when STUN protocol debugging is enabled. The issue requires access to a trusted, internal network to send the crafted packets, limiting the possibility of a successful exploit.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus
Cisco Nexus 1000V Virtual Ethernet Module (Vem) Kernel Driver
Vmware Esxi