CVE-2018-0395: Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0395?
CVE-2018-0395 is a vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software.
How does CVE-2018-0395 impact Cisco devices?
CVE-2018-0395 could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads.
What is the severity of CVE-2018-0395?
CVE-2018-0395 has a severity score of 5.3 out of 10, which is considered high.
Which software versions are affected by CVE-2018-0395?
CVE-2018-0395 affects Cisco NX-OS versions 6.0(4) and 6.1(3)s2.
How can I fix CVE-2018-0395?
To fix CVE-2018-0395, Cisco has released software updates. Please refer to the Cisco Security Advisory for more information.