CVE-2013-1178
8.3
Vector
AV:A/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 6.5 / Impact: 10.0
Source: NVD
Description
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.
Affected (135)
Products: Cisco: Nx Os, Nexus 7000, Nexus 7000 10 Slot, Nexus 7000 18 Slot, Nexus 7000 9 Slot, Mds 9000, Nexus 5000, Nexus 5010, Nexus 5020, Nexus 5548p, Nexus 5548up, Nexus 5596up, Nexus 4001i, Nexus 3000, Nexus 3016q, Nexus 3048, Nexus 3064t, Nexus 3064x, Nexus 3548, Nexus 1000v, Unified Computing System Infrastructure And Unified Computing System Software, Unified Computing System 6120xp Fabric Interconnect, Unified Computing System 6140xp Fabric Interconnect, Unified Computing System 6248up Fabric Interconnect, Unified Computing System 6296up Fabric Interconnect, Cg Os, Connected Grid Router 1000
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0(1) | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration B
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.2.(2a) | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.1.\(2\) | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 | |
| All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.0\(1x\) | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to cg4 | |
| All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.