First published: Thu Aug 29 2019(Updated: )
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Nx-os | =7.3 | |
Cisco Nx-os | =8.1 | |
Cisco Nx-os | =8.2 | |
Cisco Nx-os | =8.3 | |
Cisco MDS 9000 | ||
Cisco Mds 9100 | ||
Cisco Mds 9140 | ||
Cisco Mds 9200 | ||
Cisco Mds 9500 | ||
Cisco Mds 9700 | ||
Cisco Nx-os | =6.1\(2\)i2 | |
Cisco Nx-os | =6.1\(2\)i3 | |
Cisco Nx-os | =7.0\(3\)i4 | |
Cisco Nx-os | =7.0\(3\)i7 | |
Cisco Nx-os | =9.2 | |
Cisco Nexus 3016 | ||
Cisco Nexus 3048 | ||
Cisco Nexus 3064 | ||
Cisco Nexus 3064-t | ||
Cisco Nexus 31108pc-v | ||
Cisco Nexus 31108tc-v | ||
Cisco Nexus 31128pq | ||
Cisco Nexus 3132c-z | ||
Cisco Nexus 3132q | ||
Cisco Nexus 3132q-v | ||
Cisco Nexus 3132q-xl | ||
Cisco Nexus 3164q | ||
Cisco Nexus 3172 | ||
Cisco Nexus 3172pq-xl | ||
Cisco Nexus 3172tq | ||
Cisco Nexus 3172tq-32t | ||
Cisco Nexus 3172tq-xl | ||
Cisco Nexus 3232c | ||
Cisco Nexus 3264c-e | ||
Cisco Nexus 3264q | ||
Cisco Nexus 3408-s | ||
Cisco Nexus 34180yc | ||
Cisco Nexus 3432d-s | ||
Cisco Nexus 3464c | ||
Cisco Nexus 9000v | ||
Cisco Nexus 92160yc-x | ||
Cisco Nexus 92300yc | ||
Cisco Nexus 92304qc | ||
Cisco Nexus 92348gc-x | ||
Cisco Nexus 9236c | ||
Cisco Nexus 9272q | ||
Cisco Nexus 93108tc-ex | ||
Cisco Nexus 93108tc-fx | ||
Cisco Nexus 93120tx | ||
Cisco Nexus 93128tx | ||
Cisco Nexus 93180lc-ex | ||
Cisco Nexus 93180yc-ex | ||
Cisco Nexus 93180yc-fx | ||
Cisco Nexus 93216tc-fx2 | ||
Cisco Nexus 93240yc-fx2 | ||
Cisco Nexus 9332c | ||
Cisco Nexus 9332pq | ||
Cisco Nexus 93360yc-fx2 | ||
Cisco Nexus 9336c-fx2 | ||
Cisco Nexus 9336pq Aci Spine | ||
Cisco Nexus 9348gc-fxp | ||
Cisco Nexus 9364c | ||
Cisco Nexus 9372px | ||
Cisco Nexus 9372px-e | ||
Cisco Nexus 9372tx | ||
Cisco Nexus 9372tx-e | ||
Cisco Nexus 9396px | ||
Cisco Nexus 9396tx | ||
Cisco Nx-os | =6.0\(2\)a8 | |
Cisco Nexus 3524 | ||
Cisco Nexus 3524-x | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3548 | ||
Cisco Nexus 3548-x | ||
Cisco Nexus 3548-xl | ||
Cisco Nx-os | =7.0\(3\)f | |
Cisco Nexus 36180yc-r | ||
Cisco Nexus 3636c-r | ||
Cisco Nexus 9504 | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 | ||
Cisco Nx-os | =7.1 | |
Cisco Nx-os | =7.2 | |
Cisco Nexus 5548p | ||
Cisco Nexus 5548up | ||
Cisco Nexus 5596t | ||
Cisco Nexus 5596up | ||
Cisco Nexus 56128p | ||
Cisco Nexus 5624q | ||
Cisco Nexus 5648q | ||
Cisco Nexus 5672up | ||
Cisco Nexus 5696q | ||
Cisco Nexus 6001 | ||
Cisco Nexus 6004 | ||
Cisco Nx-os | =8.0 | |
Cisco Nexus 7000 | ||
Cisco Nexus 7000 10-slot | ||
Cisco Nexus 7000 18-slot | ||
Cisco Nexus 7000 4-slot | ||
Cisco Nexus 7000 9-slot | ||
Cisco Nexus 7700 | ||
Cisco Nexus 7700 10-slot | ||
Cisco Nexus 7700 18-slot | ||
Cisco Nexus 7700 2-slot | ||
Cisco Nexus 7700 6-slot |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.