CVE-2013-1210: Buffer Overflow
Published May 29, 2013
·Updated
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and purple screen of death) by sending crafted STUN packets to a VEM, aka Bug ID CSCud14825.
Affected Software
2 affected components
cisco NX-OS
cisco Nexus 1000V
Event History
May 29, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1210?
CVE-2013-1210 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2013-1210?
To mitigate CVE-2013-1210, disable STUN debugging in the Virtual Ethernet Module configurations.
3
What systems are affected by CVE-2013-1210?
CVE-2013-1210 affects VMware ESXi installations running on Cisco NX-OS with the Nexus 1000V.
4
What type of attack does CVE-2013-1210 facilitate?
CVE-2013-1210 allows remote attackers to cause a denial of service, resulting in an ESXi crash.
5
Can CVE-2013-1210 lead to data exposure?
CVE-2013-1210 primarily leads to system downtime and does not directly expose data.