First published: Thu Oct 06 2016(Updated: )
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | <6.0\(2\)u6\(7\) | |
Cisco NX-OS | >=6.1<7.0\(3\)i4\(1\) | |
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 31108PC-V Firmware | ||
Cisco Nexus 31108TC-V Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132Q-XL | ||
Cisco Nexus 3132Q-V Firmware | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172 Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264Q Firmware | ||
Cisco NX-OS | <7.1\(4\)n1\(1\) | |
Cisco NX-OS | >=7.2<7.2\(2\)n1\(1\) | |
Cisco NX-OS | >=7.3<7.3\(0\)n1\(1\) | |
Cisco Nexus 5548P | ||
Cisco Nexus 5548UP | ||
Cisco Nexus 5596T | ||
Cisco Nexus 5596UP | ||
Cisco 56128p | ||
Cisco Nexus 5624Q | ||
Cisco Nexus 5648Q | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5696Q | ||
Cisco Nexus 6001 Firmware | ||
Cisco Nexus 6004 Firmware | ||
Cisco NX-OS | <5.2 | |
Cisco Nexus 5010 | ||
Cisco Nexus 5020 | ||
Cisco NX-OS | <7.2\(2\)d1\(1\) | |
Cisco NX-OS | >=7.3<7.3\(1\)d1\(1\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware | ||
Cisco Nexus 7700 | ||
Cisco Nexus 7700 | ||
Cisco Nexus 7700 | ||
Cisco Nexus 7700 | ||
Cisco NX-OS | <5.2\(1\)sv3\(1.15\) | |
Cisco Nexus 1000V Switch for VMware vSphere | ||
Cisco NX-OS | >=11.0<11.1\(1j\) | |
Cisco Nexus 92160YC Switch | ||
Cisco Nexus 92304QC Firmware | ||
Cisco Nexus 9236C | ||
Cisco Nexus 9272Q Switch | ||
Cisco Nexus | ||
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128TX | ||
Cisco Nexus 93180YC-EX-24 | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus N9336PQ-X | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372TX Firmware | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9504 Firmware | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 firmware | ||
Cisco NX-OS | <6.0\(2\)a8\(1\) | |
Cisco Nexus 3524-xl | ||
Cisco Nexus 3548-X/XL Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1454 has been assigned a high severity level due to its ability to cause denial of service on vulnerable Cisco NX-OS devices.
To mitigate CVE-2016-1454, affected users should upgrade to a version of Cisco NX-OS that is not vulnerable, specifically versions above 7.3.
CVE-2016-1454 impacts various Cisco Nexus devices, including models from the 1000v series through the 9000 series running affected NX-OS versions.
Yes, CVE-2016-1454 can be exploited remotely by attackers leveraging peer relationships to send crafted BGP UPDATE messages.
The exploitation of CVE-2016-1454 can lead to a denial of service, causing the device to reload unexpectedly.