// For flags

CVE-2019-1617

Cisco Nexus 9000 Series Switches Standalone NX-OS Mode Fibre Channel over Ethernet NPV Denial of Service Vulnerability

Severity Score

7.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker could exploit this vulnerability by sending a stream of FCoE frames from an adjacent host to an affected device. An exploit could allow the attacker to cause packet amplification to occur, resulting in the saturation of interfaces and a DoS condition. Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I7(5) and 9.2(2).

Una vulnerabilidad en la implementación del protocolo Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) en el software NX-OS de Cisco podría permitir a un atacante adyacente sin autenticar provocar una condición de denegación de servicio (DoS). La vulnerabilidad se debe a un procesamiento incorrecto de paquetes FCoE cuando la funcionalidad fcoe-npv no está instalada. Un atacante podría explotar esta vulnerabilidad enviando un flujo de tramas FCoE desde un host adyacente a un dispositivo afectado. Un exploit podría permitir al atacante provocar una amplificación de paquetes, conduciendo a la saturación de interfaces y una condición DoS. Los switches de Nexus 9000 Series en modo Standalone NX-OS se ven afectados en versiones de software anteriores a las 7.0(3)I7(5) y 9.2(2).

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-03-11 CVE Published
  • 2024-07-27 EPSS Updated
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-913: Improper Control of Dynamically-Managed Code Resources
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c92160yc-x
Search vendor "Cisco" for product "N9k-c92160yc-x"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c9236c
Search vendor "Cisco" for product "N9k-c9236c"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c9272q
Search vendor "Cisco" for product "N9k-c9272q"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180lc-ex
Search vendor "Cisco" for product "N9k-c93180lc-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180yc-ex
Search vendor "Cisco" for product "N9k-c93180yc-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180yc-fx
Search vendor "Cisco" for product "N9k-c93180yc-fx"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-x9732c-ex
Search vendor "Cisco" for product "N9k-x9732c-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 9.2 < 9.2\(2\)
Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-x9736c-fx
Search vendor "Cisco" for product "N9k-x9736c-fx"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c92160yc-x
Search vendor "Cisco" for product "N9k-c92160yc-x"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c9236c
Search vendor "Cisco" for product "N9k-c9236c"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c9272q
Search vendor "Cisco" for product "N9k-c9272q"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180lc-ex
Search vendor "Cisco" for product "N9k-c93180lc-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180yc-ex
Search vendor "Cisco" for product "N9k-c93180yc-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-c93180yc-fx
Search vendor "Cisco" for product "N9k-c93180yc-fx"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-x9732c-ex
Search vendor "Cisco" for product "N9k-x9732c-ex"
--
Safe
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
>= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)
Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)"
-
Affected
in Cisco
Search vendor "Cisco"
N9k-x9736c-fx
Search vendor "Cisco" for product "N9k-x9736c-fx"
--
Safe