cisco-sa-20180620-fxnxos-fab-ace: Cisco FXOS and NX-OS Software Cisco Fabric Services Arbitrary Code Execution Vulnerability
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability exists because the affected software insufficiently validates header values in Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow that could allow the attacker to execute arbitrary code or cause a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace This advisory is part of the June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection, which includes 24 Cisco Security Advisories that describe 24 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180620-fxnxos-fab-ace?
The severity of cisco-sa-20180620-fxnxos-fab-ace is critical.
How can an attacker exploit cisco-sa-20180620-fxnxos-fab-ace?
An attacker can exploit cisco-sa-20180620-fxnxos-fab-ace by executing arbitrary code or causing a denial of service (DoS) condition.
What software versions are affected by cisco-sa-20180620-fxnxos-fab-ace?
The affected software versions for cisco-sa-20180620-fxnxos-fab-ace are: Cisco FXOS Software versions 2.2.2 up to and including 2.2.2.17, Cisco NX-OS Software versions 8.1 up to and including 8.1(1a), and Cisco NX-OS Software versions 6.2 up to and including 6.2(21).
How can I fix cisco-sa-20180620-fxnxos-fab-ace?
To fix cisco-sa-20180620-fxnxos-fab-ace, upgrade to the appropriate fixed version: 2.2.2.18 or later for Cisco FXOS Software, 8.3 or later for Cisco NX-OS Software, or 6.2(22) or later for Cisco NX-OS Software.
Where can I find more information about cisco-sa-20180620-fxnxos-fab-ace?
You can find more information about cisco-sa-20180620-fxnxos-fab-ace at the Cisco Security Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace