CVE-2019-1617
Cisco Nexus 9000 Series Switches Standalone NX-OS Mode Fibre Channel over Ethernet NPV Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker could exploit this vulnerability by sending a stream of FCoE frames from an adjacent host to an affected device. An exploit could allow the attacker to cause packet amplification to occur, resulting in the saturation of interfaces and a DoS condition. Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I7(5) and 9.2(2).
Una vulnerabilidad en la implementación del protocolo Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) en el software NX-OS de Cisco podría permitir a un atacante adyacente sin autenticar provocar una condición de denegación de servicio (DoS). La vulnerabilidad se debe a un procesamiento incorrecto de paquetes FCoE cuando la funcionalidad fcoe-npv no está instalada. Un atacante podría explotar esta vulnerabilidad enviando un flujo de tramas FCoE desde un host adyacente a un dispositivo afectado. Un exploit podría permitir al atacante provocar una amplificación de paquetes, conduciendo a la saturación de interfaces y una condición DoS. Los switches de Nexus 9000 Series en modo Standalone NX-OS se ven afectados en versiones de software anteriores a las 7.0(3)I7(5) y 9.2(2).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-06 CVE Reserved
- 2019-03-11 CVE Published
- 2024-07-27 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-913: Improper Control of Dynamically-Managed Code Resources
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107336 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-npv-dos | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c92160yc-x Search vendor "Cisco" for product "N9k-c92160yc-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c9236c Search vendor "Cisco" for product "N9k-c9236c" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c9272q Search vendor "Cisco" for product "N9k-c9272q" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180lc-ex Search vendor "Cisco" for product "N9k-c93180lc-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180yc-ex Search vendor "Cisco" for product "N9k-c93180yc-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180yc-fx Search vendor "Cisco" for product "N9k-c93180yc-fx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-x9732c-ex Search vendor "Cisco" for product "N9k-x9732c-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 9.2 < 9.2\(2\) Search vendor "Cisco" for product "Nx-os" and version " >= 9.2 < 9.2\(2\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-x9736c-fx Search vendor "Cisco" for product "N9k-x9736c-fx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c92160yc-x Search vendor "Cisco" for product "N9k-c92160yc-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c9236c Search vendor "Cisco" for product "N9k-c9236c" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c9272q Search vendor "Cisco" for product "N9k-c9272q" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180lc-ex Search vendor "Cisco" for product "N9k-c93180lc-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180yc-ex Search vendor "Cisco" for product "N9k-c93180yc-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-c93180yc-fx Search vendor "Cisco" for product "N9k-c93180yc-fx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-x9732c-ex Search vendor "Cisco" for product "N9k-x9732c-ex" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | N9k-x9736c-fx Search vendor "Cisco" for product "N9k-x9736c-fx" | - | - |
Safe
|