PT-2016-4813 · Vmware+1 · Esxi+2
Published
2016-07-27
·
Updated
2017-09-01
·
CVE-2016-1465
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 1000v Application Virtual Switch (AVS) versions prior to 5.2(1)SV3(1.5i)
Description
A denial of service issue exists due to insufficient input validation of Cisco Discovery Protocol packets, which could result in an out-of-bounds memory access and cause the ESXi hypervisor to crash, displaying a purple diagnostic screen. An attacker could exploit this by sending a crafted Cisco Discovery Protocol packet to a targeted device, resulting in a denial of service condition.
Recommendations
For versions prior to 5.2(1)SV3(1.5i), update to version 5.2(1)SV3(1.5i) or later to resolve the issue. As a temporary workaround, consider restricting access to the Cisco Discovery Protocol to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus
Cisco Nexus 1000V Application Virtual Switch
Esxi