PT-2016-4801 · Cisco · Cisco Nx-Os+1
Published
2016-10-05
·
Updated
2022-06-05
·
CVE-2016-1453
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS versions 5.0 through 7.3
Description
A buffer overflow issue in the Overlay Transport Virtualization (OTV) GRE feature allows remote attackers to execute arbitrary code via long parameters in a packet header. The vulnerability is due to incomplete input validation performed on the size of OTV packet header parameters, which can result in a buffer overflow. An attacker could exploit this vulnerability by sending a crafted OTV UDP packet to the OTV interface on an affected device, potentially allowing the attacker to execute arbitrary code and obtain full control of the system or cause a reload of the OTV related process on the affected device.
Recommendations
For Cisco NX-OS versions 5.0 through 7.3, update to a fixed software version to address this issue. As a temporary workaround, consider implementing a mitigation strategy to restrict the sending of crafted OTV UDP packets to the OTV interface on affected devices.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus