cisco-sa-20190306-nxos-fabric-dos: Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-fabric-dos
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco NX-OS Software vulnerability?
The vulnerability ID is cisco-sa-20190306-nxos-fabric-dos.
What is the severity rating of cisco-sa-20190306-nxos-fabric-dos?
The severity rating of cisco-sa-20190306-nxos-fabric-dos is 8.6.
How does cisco-sa-20190306-nxos-fabric-dos affect Cisco NX-OS Software?
cisco-sa-20190306-nxos-fabric-dos affects Cisco NX-OS Software by allowing an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition.
Which versions of Cisco NX-OS Software are affected by cisco-sa-20190306-nxos-fabric-dos?
The versions affected by cisco-sa-20190306-nxos-fabric-dos are 8.1(1b), 6.2(25), 6.0(2)A8(10), 7.0(3)F3(3c)1, Umbrella SMU for CSCvj10178 and CSCvj638071, and 4.0(2a), among others.
Is there a fix available for cisco-sa-20190306-nxos-fabric-dos?
Yes, Cisco has provided fixes for cisco-sa-20190306-nxos-fabric-dos. Please refer to the Cisco Security Advisory for more information.