PT-2019-2152 · Cisco · Cisco Nx-Os+2
Published
2019-05-15
·
Updated
2023-04-20
·
CVE-2019-1858
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco FXOS Software (affected versions not specified)
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, leading to an affected device restarting unexpectedly. The issue is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this by sending multiple crafted SNMP packets to an affected device, causing the SNMP application to leak system memory over time. This could result in the SNMP application restarting multiple times, leading to a system-level restart and a denial of service (DoS) condition.
Recommendations
For Cisco FXOS Software, update to a version that includes the fix for this issue.
For Cisco NX-OS Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SNMP application to minimize the risk of exploitation.
Fix
DoS
Improper Handling of Exceptional Conditions
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Fxos
Cisco Nx-Os
Cisco Nexus