PT-2019-1559 · Cisco · Firepower 4100 Series Next-Generation Firewalls+12

Published

2019-03-06

·

Updated

2023-04-20

·

CVE-2019-1597

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75 Cisco NX-OS Software versions prior to 7.0(3)I7(1) on Nexus 3000 Series Switches Cisco NX-OS Software versions prior to 7.0(3)I7(2) on Nexus 3500 Platform Switches Cisco NX-OS Software versions prior to 8.2(1) on MDS 9000 Series Multilayer Switches and Nexus 7000 and 7700 Series Switches Cisco NX-OS Software versions prior to 7.0(3)I7(1) on Nexus 9000 Series Switches in Standalone NX-OS Mode Cisco UCS 6200 and 6300 Fabric Interconnect devices versions prior to 3.2(2b) Firepower 4100 Series Next-Generation Firewalls versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75 Firepower 9300 Security Appliances versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75
Description Multiple vulnerabilities exist in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software due to improper parsing of LDAP packets by an affected device. An unauthenticated, remote attacker could exploit these vulnerabilities by sending an LDAP packet crafted using Basic Encoding Rules (BER) to an affected device, causing the device to reload and resulting in a denial of service (DoS) condition. The LDAP packet must have a source IP address of an LDAP server configured on the targeted device.
Recommendations For Cisco FXOS Software versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75, update to a fixed version. For Cisco NX-OS Software versions prior to 7.0(3)I7(1) on Nexus 3000 Series Switches, update to a fixed version. For Cisco NX-OS Software versions prior to 7.0(3)I7(2) on Nexus 3500 Platform Switches, update to a fixed version. For Cisco NX-OS Software versions prior to 8.2(1) on MDS 9000 Series Multilayer Switches and Nexus 7000 and 7700 Series Switches, update to a fixed version. For Cisco NX-OS Software versions prior to 7.0(3)I7(1) on Nexus 9000 Series Switches in Standalone NX-OS Mode, update to a fixed version. For Cisco UCS 6200 and 6300 Fabric Interconnect devices versions prior to 3.2(2b), update to a fixed version. For Firepower 4100 Series Next-Generation Firewalls versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75, update to a fixed version. For Firepower 9300 Security Appliances versions prior to 2.0.1.201, 2.2.2.54, and 2.3.1.75, update to a fixed version.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2019-01090
CVE-2019-1597

Affected Products

Cisco Fxos
Cisco Nx-Os
Cisco Nexus
Cisco Ucs 6200
Cisco Ucs 6300
Firepower 4100 Series Next-Generation Firewalls
Firepower 9300 Security Appliance
Mds 9000 Series Multilayer Switches
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches