First published: Fri Mar 17 2017(Updated: )
A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCuy25824. Known Affected Releases: 7.0(3)I3(1) 8.3(0)CV(0.342) 8.3(0)CV(0.345). Known Fixed Releases: 8.3(0)CV(0.362) 8.0(1) 7.0(3)IED5(0.19) 7.0(3)IED5(0) 7.0(3)I4(1) 7.0(3)I4(0.8) 7.0(3)I2(2e) 7.0(3)F1(1.22) 7.0(3)F1(1) 7.0(3)F1(0.230).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =7.0\(3\)i3\(0.170\) | |
Cisco NX-OS | =8.3\(0\)cv\(0.342\) | |
Cisco NX-OS | =8.3\(0\)cv\(0.345\) | |
Cisco Nexus 92160YC-X Firmware | ||
Cisco Nexus 92300YC Firmware | ||
Cisco Nexus 92304qc | ||
Cisco Nexus 9236c | ||
Cisco Nexus 9272Q Switch | ||
Cisco Nexus 93108TC-EX-24 | ||
Cisco Nexus 93120TX | ||
Cisco Nexus 93128tx | ||
Cisco Nexus 9000 Series Switch | ||
Cisco Nexus 93180YC-EX-24 | ||
Cisco Nexus 9332pq | ||
Cisco Nexus 9336PQ | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372px | ||
Cisco Nexus 9372TX-E | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9396PX Switch | ||
Cisco Nexus 9396TX | ||
Cisco Nexus 9508 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3879 is classified as a Denial of Service vulnerability.
To fix CVE-2017-3879, update your Cisco NX-OS Software to a patched version.
Devices running affected versions of Cisco NX-OS Software, specifically Cisco Nexus 9000 Series Switches, are at risk.
Yes, CVE-2017-3879 can be exploited by unauthenticated remote attackers.
CVE-2017-3879 can cause the login process to terminate unexpectedly, resulting in failed login attempts.