CVE-2019-1967: Cisco NX-OS Software Network Time Protocol Denial of Service Vulnerability
A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources when the affected device is logging a drop action for received MODEPRIVATE (Mode 7) NTP packets. An attacker could exploit this vulnerability by flooding the device with a steady stream of Mode 7 NTP packets. A successful exploit could allow the attacker to cause high CPU and memory usage on the affected device, which could cause internal system processes to restart or cause the affected device to unexpectedly reload. Note: The NTP feature is enabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1967?
CVE-2019-1967 has been assigned a high severity rating due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2019-1967?
To fix CVE-2019-1967, you need to apply the security patches provided by Cisco for affected NX-OS software versions.
What versions of Cisco NX-OS are affected by CVE-2019-1967?
CVE-2019-1967 affects Cisco NX-OS versions 6.2, 7.3, 8.1, 8.2, 8.3 and several other specific releases.
What are the potential impacts of CVE-2019-1967?
Successful exploitation of CVE-2019-1967 can lead to exhaustion of system resources, resulting in a denial of service for the affected device.
Is there a workaround for CVE-2019-1967?
Cisco recommends disabling the NTP service if it is not needed as a temporary workaround for CVE-2019-1967.