PT-2019-1561 · Cisco · Ucs 6200/6300 Series Fabric Interconnect+3

Published

2019-03-06

·

Updated

2020-10-08

·

CVE-2019-1599

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software versions prior to 5.2(1)SM3(2.1) Cisco NX-OS Software versions prior to 5.2(1)SV3(4.1a) Cisco NX-OS Software versions prior to 7.0(3)I7(6) Cisco NX-OS Software versions prior to 7.1(5)N1(1b) Cisco NX-OS Software versions prior to 7.3(5)N1(1) Cisco NX-OS Software versions prior to 9.2(2) Cisco NX-OS Software versions prior to 6.0(2)A8(11) Cisco NX-OS Software versions prior to 6.2(22) Cisco NX-OS Software versions prior to 7.0(3)F3(5) UCS 6200 and 6300 Series Fabric Interconnect versions prior to 3.2(3j) UCS 6200 and 6300 Series Fabric Interconnect versions prior to 4.0(2a) UCS 6400 Series Fabric Interconnect versions prior to 4.0(2a)
Description A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could exploit this vulnerability by sending crafted TCP streams to an affected device in a sustained way. A successful exploit could cause the network stack of an affected device to run out of available buffers, impairing operations of control plane and management plane protocols, resulting in a DoS condition. This vulnerability can be triggered only by traffic that is destined to an affected device and cannot be exploited using traffic that transits an affected device.
Recommendations For Cisco NX-OS Software versions prior to 5.2(1)SM3(2.1), update to version 5.2(1)SM3(2.1) or later. For Cisco NX-OS Software versions prior to 5.2(1)SV3(4.1a), update to version 5.2(1)SV3(4.1a) or later. For Cisco NX-OS Software versions prior to 7.0(3)I7(6), update to version 7.0(3)I7(6) or later. For Cisco NX-OS Software versions prior to 7.1(5)N1(1b), update to version 7.1(5)N1(1b) or later. For Cisco NX-OS Software versions prior to 7.3(5)N1(1), update to version 7.3(5)N1(1) or later. For Cisco NX-OS Software versions prior to 9.2(2), update to version 9.2(2) or later. For Cisco NX-OS Software versions prior to 6.0(2)A8(11), update to version 6.0(2)A8(11) or later. For Cisco NX-OS Software versions prior to 6.2(22), update to version 6.2(22) or later. For Cisco NX-OS Software versions prior to 7.0(3)F3(5), update to version 7.0(3)F3(5) or later. For UCS 6200 and 6300 Series Fabric Interconnect versions prior to 3.2(3j), update to version 3.2(3j) or later. For UCS 6200 and 6300 Series Fabric Interconnect versions prior to 4.0(2a), update to version 4.0(2a) or later. For UCS 6400 Series Fabric Interconnect versions prior to 4.0(2a), update to version 4.0(2a) or later.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01092
CVE-2019-1599

Affected Products

Cisco Nx-Os
Cisco Nexus
Ucs 6200/6300 Series Fabric Interconnect
Ucs 6400 Series Fabric Interconnect