cisco-sa-20180620-nxos-bo: Cisco NX-OS Software NX-API Arbitrary Code Execution Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, causing a buffer overflow.
The vulnerability is due to incorrect input validation in the authentication module of the NX-API subsystem. An attacker could exploit this vulnerability by sending a crafted HTTP or HTTPS packet to the management interface of an affected system with the NX-API feature enabled. An exploit could allow the attacker to execute arbitrary code as root. Note: NX-API is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo This advisory is part of the June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection, which includes 24 Cisco Security Advisories that describe 24 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180620-nxos-bo?
The severity of cisco-sa-20180620-nxos-bo is critical due to the potential for unauthenticated remote code execution.
How do I fix cisco-sa-20180620-nxos-bo?
To mitigate cisco-sa-20180620-nxos-bo, it is recommended to upgrade Cisco NX-OS Software to the latest version that addresses this vulnerability.
What systems are affected by cisco-sa-20180620-nxos-bo?
cisco-sa-20180620-nxos-bo affects Cisco NX-OS Software versions that utilize the NX-API feature.
Can cisco-sa-20180620-nxos-bo be exploited remotely?
Yes, cisco-sa-20180620-nxos-bo can be exploited remotely by an unauthenticated attacker.
What type of attack is associated with cisco-sa-20180620-nxos-bo?
cisco-sa-20180620-nxos-bo is associated with a buffer overflow attack due to improper input validation.