CVE-2011-4023: High severity cisco nx-os vulnerability
Published May 3, 2012
·Updated
Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.
Affected Software
27 affected components
Cisco NX-OS=5.0
Cisco NX-OS=5.0\(2\)
Cisco NX-OS=5.0\(2\)n1\(1\)
Cisco NX-OS=5.0\(2\)n2\(1\)
Cisco NX-OS=5.0\(2\)n2\(1a\)
Cisco NX-OS=5.0\(2a\)
Cisco NX-OS=5.0\(3\)
Cisco NX-OS=5.0\(3\)n1\(1\)
Cisco NX-OS=5.0\(3\)n1\(1a\)
Cisco NX-OS=5.0\(3\)n1\(1b\)
Cisco NX-OS=5.0\(3\)n1\(1c\)
Cisco NX-OS=5.0\(3\)n2\(1\)
Cisco NX-OS=5.0\(3\)n2\(2\)
Cisco NX-OS=5.0\(3\)n2\(2a\)
Cisco NX-OS=5.0\(3\)n2\(2b\)
Cisco NX-OS=5.0\(5\)
Cisco Nexus 2148t Fex Switch
Cisco Nexus 2224tp Fex Switch
Cisco Nexus 2232pp Fex Switch
Cisco Nexus 2232tm Fex Switch
Cisco Nexus 2248tp E Fex Switch
Cisco Nexus 2248tp Fex Switch
Cisco Nexus 5010p Switch
Cisco Nexus 5020p Switch
Cisco Nexus 5548p
Cisco Nexus 5548up
Cisco Nexus 5596up
Event History
May 3, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:11 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4023?
CVE-2011-4023 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2011-4023?
To mitigate CVE-2011-4023, Cisco recommends upgrading to a fixed version of NX-OS that addresses the memory leak issue.
3
Who is affected by CVE-2011-4023?
CVE-2011-4023 affects remote authenticated users of Cisco NX-OS 5.0 on various Nexus switch models.
4
What type of attacks can CVE-2011-4023 facilitate?
CVE-2011-4023 can facilitate denial of service attacks by causing excessive memory consumption through SNMP requests.
5
What is the cause of CVE-2011-4023?
CVE-2011-4023 is caused by a memory leak in the libcmd component of Cisco NX-OS, which can be triggered via SNMP.