CVE-2019-1968: Cisco NX-OS Software NX-API Denial of Service Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1968?
CVE-2019-1968 has been rated as High severity due to its potential for unauthenticated remote system process restarts.
How do I fix CVE-2019-1968?
To fix CVE-2019-1968, upgrade your Cisco NX-OS Software to a version that addresses this vulnerability.
Who is affected by CVE-2019-1968?
Cisco NX-OS versions 6.1, 7.0, 7.1, 7.2, 7.3, 8.0, 8.1, 8.2, and 8.3 are vulnerable to CVE-2019-1968.
What vulnerabilities are associated with CVE-2019-1968?
CVE-2019-1968 is primarily a denial-of-service vulnerability leading to unexpected restarts of NX-API processes.
Can CVE-2019-1968 be exploited without authentication?
Yes, CVE-2019-1968 can be exploited by an unauthenticated remote attacker.