cisco-sa-20190828-fxnxos-snmp-dos: Cisco FXOS and NX-OS Software Authenticated Simple Network Management Protocol Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of Abstract Syntax Notation One (ASN.1)-encoded variables in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the SNMP daemon on the affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-fxnxos-snmp-dos
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco vulnerability?
The vulnerability ID for this Cisco vulnerability is cisco-sa-20190828-fxnxos-snmp-dos.
What is the severity of the vulnerability cisco-sa-20190828-fxnxos-snmp-dos?
The severity of the vulnerability cisco-sa-20190828-fxnxos-snmp-dos is high, with a severity value of 7.7.
Which software versions are affected by the vulnerability cisco-sa-20190828-fxnxos-snmp-dos?
The Cisco FXOS Software versions 2.4.1.222, 2.3.1.130, and 2.2.2.91 are affected by the vulnerability. The Cisco NX-OS Software versions 6.2(29) and 5.2(1)SV3(4.1a) are also affected by the vulnerability.
How can an authenticated, remote attacker exploit the vulnerability cisco-sa-20190828-fxnxos-snmp-dos?
An authenticated, remote attacker can exploit the vulnerability cisco-sa-20190828-fxnxos-snmp-dos by sending malicious SNMP packets to the affected device, causing the SNMP application to restart unexpectedly.
Where can I find more information about the vulnerability cisco-sa-20190828-fxnxos-snmp-dos?
You can find more information about the vulnerability cisco-sa-20190828-fxnxos-snmp-dos on the Cisco Security Advisory page: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-fxnxos-snmp-dos