First published: Fri Mar 17 2017(Updated: )
A Denial of Service vulnerability in the Telnet remote login functionality of Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a Telnet process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCux46778. Known Affected Releases: 7.0(3)I3(0.170). Known Fixed Releases: 7.0(3)I3(1) 7.0(3)I3(0.257) 7.0(3)I3(0.255) 7.0(3)I2(2e) 7.0(3)F1(1.22) 7.0(3)F1(1).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Nx-os | =7.0\(3\)i3\(0.170\) | |
Cisco Nexus 92160yc Switch | ||
Cisco Nexus 92300yc Switch | ||
Cisco Nexus 92304qc Switch | ||
Cisco Nexus 9236c Switch | ||
Cisco Nexus 9272q Switch | ||
Cisco Nexus 93108tc-ex Switch | ||
Cisco Nexus 93120tx Switch | ||
Cisco Nexus 93128tx Switch | ||
Cisco Nexus 93180lc-ex Switch | ||
Cisco Nexus 93180yc-ex Switch | ||
Cisco Nexus 9332pq Switch | ||
Cisco Nexus 9336pq Aci Spine Switch | ||
Cisco Nexus 9372px-e Switch | ||
Cisco Nexus 9372px Switch | ||
Cisco Nexus 9372tx-e Switch | ||
Cisco Nexus 9372tx Switch | ||
Cisco Nexus 9396px Switch | ||
Cisco Nexus 9396tx Switch | ||
Cisco Nexus 9508 Switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-3878 is rated as medium with a score of 5.3.
CVE-2017-3878 affects Cisco NX-OS Software version 7.0(3)i3(0.170) on Cisco Nexus 9000 Series Switches.
CVE-2017-3878 allows an unauthenticated remote attacker to cause a Telnet process to terminate unexpectedly, leading to denial of service.
To fix CVE-2017-3878, upgrade the Cisco NX-OS Software to a version that addresses the vulnerability.
Currently, there are no documented workarounds for mitigating the effects of CVE-2017-3878.