PT-2019-2152 · Cisco · Cisco Nx-Os+2

Published

2019-05-15

·

Updated

2023-04-20

·

CVE-2019-1858

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software (affected versions not specified) Cisco NX-OS Software (affected versions not specified)
Description A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, leading to an affected device restarting unexpectedly. The issue is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this by sending multiple crafted SNMP packets to an affected device, causing the SNMP application to leak system memory over time. This could result in the SNMP application restarting multiple times, leading to a system-level restart and a denial of service (DoS) condition.
Recommendations For Cisco FXOS Software, update to a version that includes the fix for this issue. For Cisco NX-OS Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SNMP application to minimize the risk of exploitation.

Fix

DoS

Improper Handling of Exceptional Conditions

RCE

Weakness Enumeration

Related Identifiers

BDU:2019-01918
CVE-2019-1858

Affected Products

Cisco Fxos
Cisco Nx-Os
Cisco Nexus