CVE-2018-0299: Input Validation
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg10442.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0299?
CVE-2018-0299 is classified as a high severity vulnerability due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2018-0299?
To mitigate CVE-2018-0299, upgrade to a fixed release of Cisco NX-OS that addresses this vulnerability.
Who is affected by CVE-2018-0299?
CVE-2018-0299 affects devices running Cisco NX-OS version 4.1(2)e1(1r) in the Cisco Nexus 4000 Series Switch.
What is the impact of CVE-2018-0299?
The impact of CVE-2018-0299 is that it allows an authenticated, remote attacker to cause the affected device to reload unexpectedly.
Is CVE-2018-0299 exploitable remotely?
Yes, CVE-2018-0299 can be exploited remotely by an authenticated attacker.