CVE-2018-0378: Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of protection against PTP frame flood attacks. An attacker could exploit this vulnerability by sending large streams of malicious IPv4 or IPv6 PTP traffic to the affected device. A successful exploit could allow the attacker to cause a DoS condition, impacting the traffic passing through the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0378?
CVE-2018-0378 is a vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
How does CVE-2018-0378 affect Cisco Nexus switches?
CVE-2018-0378 affects Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software.
What is the severity of CVE-2018-0378?
CVE-2018-0378 has a severity rating of 8.6 (high).
How can an attacker exploit CVE-2018-0378?
An attacker can exploit CVE-2018-0378 by sending specially crafted Precision Time Protocol (PTP) packets to the affected device.
Is there a fix available for CVE-2018-0378?
Yes, Cisco has released a security advisory with mitigation steps for CVE-2018-0378.