CVE-2017-3878: Buffer Overflow
A Denial of Service vulnerability in the Telnet remote login functionality of Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a Telnet process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCux46778. Known Affected Releases: 7.0(3)I3(0.170). Known Fixed Releases: 7.0(3)I3(1) 7.0(3)I3(0.257) 7.0(3)I3(0.255) 7.0(3)I2(2e) 7.0(3)F1(1.22) 7.0(3)F1(1).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)I3(1) - Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)I3(0.257) - Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)I3(0.255) - Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)I2(2e) - Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)F1(1.22) - Upgrade
Upgrade
Cisco NX-OS on Cisco Nexus 9000 Series Switchesto a version that resolves this vulnerability.Fixed in 7.0(3)F1(1) - Compensating control
Ensure the device is not configured to allow remote Telnet connections to the device (Telnet remote login functionality) until the affected NX-OS release is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3878?
The severity of CVE-2017-3878 is rated as medium with a score of 5.3.
What systems are affected by CVE-2017-3878?
CVE-2017-3878 affects Cisco NX-OS Software version 7.0(3)i3(0.170) on Cisco Nexus 9000 Series Switches.
How does CVE-2017-3878 impact system security?
CVE-2017-3878 allows an unauthenticated remote attacker to cause a Telnet process to terminate unexpectedly, leading to denial of service.
How do I fix CVE-2017-3878?
To fix CVE-2017-3878, upgrade the Cisco NX-OS Software to a version that addresses the vulnerability.
Is there a workaround for CVE-2017-3878?
Currently, there are no documented workarounds for mitigating the effects of CVE-2017-3878.