// For flags

CVE-2018-0299

 

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg10442.

Una vulnerabilidad en la funcionalidad SNMP (Simple Network Management Protocol) de Cisco NX-OS en Cisco Nexus 4000 Series Switch podría permitir que un atacante remoto autenticado haga que se reinicie el dispositivo de manera inesperada, provocando una condición de denegación de servicio (DoS). La vulnerabilidad se debe a la validación incompleta de una petición de sondeo SNMP para un MIB en concreto. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición de sondeo SNMP específica al dispositivo objetivo. Este exploit podría permitir que el atacante consiga que el dispositivo se reinicie, provocando una denegación de servicio (DoS). Cisco Bug IDs: CSCvg10442.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-27 CVE Reserved
  • 2018-06-21 CVE Published
  • 2024-04-30 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
4.1\(2\)e1\(1r\)
Search vendor "Cisco" for product "Nx-os" and version "4.1\(2\)e1\(1r\)"
-
Affected
in Cisco
Search vendor "Cisco"
Nexus 4001i
Search vendor "Cisco" for product "Nexus 4001i"
--
Safe