You are here
Home > Preporuke > Ranjivost Cisco Nexus 9000 serije preklopnika

Ranjivost Cisco Nexus 9000 serije preklopnika

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Cisco Security Advisory: Cisco Nexus 9000 Series ACI Mode Switch Software Link Layer Discovery Protocol Buffer Overflow Vulnerability

Advisory ID: cisco-sa-20190731-nxos-bo

Revision: 1.0

For Public Release: 2019 July 31 16:00 GMT

Last Updated: 2019 July 31 16:00 GMT

CVE ID(s): CVE-2019-1901

CVSS Score v(3): 8.8 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

+———————————————————————

Summary

=======

A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges.

The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges.

Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo [“https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo”]

—–BEGIN PGP SIGNATURE—–

iQJ5BAEBAgBjBQJdQbtBXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50
IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly
dEBjaXNjby5jb20+AAoJEJa12PPJBfczQQUP/1VobeEtedogbuxbwYO8Nscb3M65
QCgL4An1EKVXbBGbcNtc4wfsfeO33yT7QhPKCApdHmBVF6w8ZJYHN4gbQNUXPek7
nKBvFOtlmutvTju6UdBCNjgFuQFe9V0cZWJWjCAuUQN9S0O4bG7Y0pTqdPaZt85U
yos/poUFPKWUIf91ZlctbTF1pxnzdfrYY/ybpSvOzbZGH2HwRa49XiSuCCPLq45x
HwZS+04ROZjmcsRPhijlr5tW1Q2idC9kY45atsf1R2HtPXanFTktPqeMUEeG3Q55
zlTXnCSe36xdc6b5lfWQD1Fx3LY9yTfX2YXlGWNE6YHiqEGd6Q38ymAMMJfbieMb
Sl2wEUJQOrEbHFVm74hTRhiLP7Ctt3BH8bF2Fco5MK76iKStv9GDv+IZf66JWQt7
1ulkye4TCvfREN/APc8LJRwAcmS8Q5ZUvFJfHRLjMjVOhWG5JWWEw9Np3lbLBx81
tl5W1URvow7jkQYOMM/5Wb2yM1PsxPL+bT7SU4adlIhVMNv0/uES/aqnKzMYYYch
ZWMV7KgQxs8nkTGUQ9AEXS+yI68d2YkGJps9RsNGeiroptMpKVO3E3q14Rbx7BsE
yR4unPzhbZO2jSG2SdS47oKqG2CmV3CYeNUkSD5WP2Nf3u0YCCqpPf1jyX3zkW72
EFWInRnO6t+FAQSk
=kqnp
—–END PGP SIGNATURE—–

_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa ProFTPD

Otkriven je sigurnosni nedostatak u programskom paketu ProFTPD za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close