First published: Wed Aug 19 2015(Updated: )
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =7.3\(0\)zn\(0.81\) | |
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 3064 Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132Q-XL | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172 Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264Q Firmware | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3548-X/XL Firmware | ||
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128 Firmware | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus N9336PQ-X | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9504 firmware | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 firmware | ||
Cisco Nexus 1000V for Hyper-V | ||
Cisco NX-OS | =4.1\(2\)e1\(1c\) | |
Cisco Nexus 4001i | ||
Cisco NX-OS | =7.2\(0\)n1\(0.1\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7700 series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4324 is classified as a high severity vulnerability due to its potential to cause denial of service on affected devices.
To mitigate CVE-2015-4324, upgrade to the recommended fixed versions of Cisco NX-OS that address the buffer overflow issue.
CVE-2015-4324 affects several Cisco Nexus devices including Nexus 1000V, Nexus 3000, Nexus 4000, Nexus 7000, and Nexus 9000 that run specific versions of NX-OS.
CVE-2015-4324 is caused by a buffer overflow condition in the IGMP process within the affected versions of Cisco NX-OS.
There are no known workarounds for CVE-2015-4324; users are advised to apply the necessary updates to resolve this vulnerability.