PT-2014-5233 · Cisco · Cisco Nx-Os+1

Published

2014-08-18

·

Updated

2017-08-29

·

CVE-2014-3341

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco NX-OS versions 7.0(3)N1(1) and earlier
Description A vulnerability in the Simple Network Management Protocol (SNMP) module of Cisco NX-OS Software could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to a failure to respond to invalid requests in the same manner when specifying a VLAN ID. An attacker could exploit this vulnerability by making a large number of requests to the listening SNMP port of an affected device. A successful exploit could allow the attacker to enumerate VLANs that are configured on the affected device. This issue affects Cisco Nexus 5000 Series and Cisco Nexus 6000 Series devices.
Recommendations For Cisco NX-OS versions 7.0(3)N1(1) and earlier, update to a newer version of Cisco NX-OS Software that includes the fix for this issue. As a temporary workaround, consider restricting access to the SNMP module to minimize the risk of exploitation. Additionally, limit the number of requests to the SNMP port to reduce the likelihood of a successful exploit.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3341

Affected Products

Cisco Nx-Os
Cisco Nexus