PT-2018-3872 · Cisco · Nexus 5500 Platform Switches+18

Published

2018-06-20

·

Updated

2023-04-20

·

CVE-2018-0311

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software and Cisco NX-OS Software (affected versions not specified) Firepower 4100 Series Next-Generation Firewalls (affected versions not specified) Firepower 9300 Security Appliance (affected versions not specified) MDS 9000 Series Multilayer Switches (affected versions not specified) Nexus 2000 Series Fabric Extenders (affected versions not specified) Nexus 3000 Series Switches (affected versions not specified) Nexus 3500 Platform Switches (affected versions not specified) Nexus 5500 Platform Switches (affected versions not specified) Nexus 5600 Platform Switches (affected versions not specified) Nexus 6000 Series Switches (affected versions not specified) Nexus 7000 Series Switches (affected versions not specified) Nexus 7700 Series Switches (affected versions not specified) Nexus 9000 Series Switches in standalone NX-OS mode (affected versions not specified) Nexus 9500 R-Series Line Cards and Fabric Modules (affected versions not specified) UCS 6100 Series Fabric Interconnects (affected versions not specified) UCS 6200 Series Fabric Interconnects (affected versions not specified) UCS 6300 Series Fabric Interconnects (affected versions not specified)
Description A vulnerability in the Cisco Fabric Services component could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packets when the software processes packet data. An attacker could exploit this vulnerability by sending a maliciously crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the device, which could cause process crashes and result in a DoS condition on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-02366
CVE-2018-0311

Affected Products

Cisco Fxos
Cisco Nx-Os
Cisco Nexus
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
Mds 9000 Series Multilayer Switches
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches
Nexus 9500 R-Series Line Cards/Fabric Modules
Ucs 6100 Series Fabric Interconnects
Ucs 6200 Series Fabric Interconnects
Ucs 6300 Series Fabric Interconnects