CVE-2017-3879: Buffer Overflow
A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCuy25824. Known Affected Releases: 7.0(3)I3(1) 8.3(0)CV(0.342) 8.3(0)CV(0.345). Known Fixed Releases: 8.3(0)CV(0.362) 8.0(1) 7.0(3)IED5(0.19) 7.0(3)IED5(0) 7.0(3)I4(1) 7.0(3)I4(0.8) 7.0(3)I2(2e) 7.0(3)F1(1.22) 7.0(3)F1(1) 7.0(3)F1(0.230).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 8.3(0)CV(0.362) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 8.0(1) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)IED5(0.19) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)IED5(0) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)I4(1) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)I4(0.8) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)I2(2e) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)F1(1.22) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)F1(1) - Upgrade
Upgrade
Cisco NX-OS Software (Cisco Nexus 9000 Series Switches)to a version that resolves this vulnerability.Fixed in 7.0(3)F1(0.230) - Compensating control
Ensure Cisco Nexus 9000 switches running affected Cisco NX-OS releases are not configured to allow remote Telnet connections to the device; attackers may use either Telnet or SSH for remote login attempts.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3879?
CVE-2017-3879 is classified as a Denial of Service vulnerability.
How do I fix CVE-2017-3879?
To fix CVE-2017-3879, update your Cisco NX-OS Software to a patched version.
Which devices are affected by CVE-2017-3879?
Devices running affected versions of Cisco NX-OS Software, specifically Cisco Nexus 9000 Series Switches, are at risk.
Can CVE-2017-3879 be exploited remotely?
Yes, CVE-2017-3879 can be exploited by unauthenticated remote attackers.
What impact does CVE-2017-3879 have on Cisco NX-OS Software?
CVE-2017-3879 can cause the login process to terminate unexpectedly, resulting in failed login attempts.