First published: Thu Oct 19 2017(Updated: )
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Firepower Extensible Operating System | <=2.3 | |
Cisco Firepower 4100 Series | ||
Cisco FX-OS | =2.3 | |
Cisco Firepower 9300 firmware | ||
Cisco NX-OS | =5.2 | |
Cisco NX-OS | =6.2 | |
Cisco NX-OS | =6.3 | |
Cisco NX-OS | =7.3 | |
Cisco NX-OS | =8.1 | |
Cisco NX-OS | =8.2 | |
Cisco MDS 9000 Series Multilayer Switches | ||
Cisco NX-OS | <=4.1 | |
Cisco Nexus 1000V for Hyper-V | ||
Cisco Nexus 1100v | ||
Cisco NX-OS | <=6.0 | |
Cisco NX-OS | =7.0 | |
Cisco Nexus 3000 | ||
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 3064 Firmware | ||
Cisco Nexus 3064 | ||
Cisco Nexus 3064-X Firmware | ||
Cisco NX-OS | =7.0\(3\)i3\(1\) | |
Cisco Nexus 3500 Platform | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3548-X/XL Firmware | ||
Cisco NX-OS | <=5.2 | |
Cisco Nexus 2000 | ||
Cisco Nexus 5000 firmware | ||
Cisco Nexus 5010 | ||
Cisco Nexus 5010 | ||
Cisco NX-OS for Nexus 5500 Platform Switches | ||
Cisco Nexus 5548P Firmware | ||
Cisco Nexus 5548UP Firmware | ||
Cisco Nexus 5596T Firmware | ||
Cisco Nexus 5596UP Firmware | ||
Cisco Nexus 5600 Firmware | ||
Cisco 56128p | ||
Cisco Nexus 5624Q Firmware | ||
Cisco Nexus 5648Q Firmware | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5696Q Firmware | ||
Cisco Nexus 6000 firmware | ||
Cisco Nexus 6001 Firmware | ||
Cisco Nexus 6004 Firmware | ||
Cisco Nexus 6004X Firmware | ||
Cisco NX-OS | =7.1\(0.1\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware | ||
Cisco Nexus 7700 series | ||
Cisco NX-OS | =6.1 | |
Cisco Nexus 9000 Firmware | ||
Cisco Catalyst 9500 Series Switches | ||
Cisco NX-OS | <=2.2 | |
Cisco NX-OS | =2.5 | |
Cisco NX-OS | =3.0 | |
Cisco NX-OS | =3.1 | |
Cisco NX-OS | =3.2 | |
Cisco UCS 6100 | ||
Cisco UCS 6200 firmware | ||
Cisco UCS 6300 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3883 has been classified as a medium severity vulnerability.
To remediate CVE-2017-3883, update your Cisco Firepower Extensible Operating System or NX-OS to the latest patched version.
CVE-2017-3883 affects devices running Cisco Firepower Extensible Operating System versions up to 2.3 and various versions of Cisco NX-OS.
CVE-2017-3883 allows an unauthenticated remote attacker to trigger a device reload through malicious requests.
Yes, CVE-2017-3883 can potentially be exploited by an attacker over the Internet due to the nature of the vulnerability.