← Back

CVE-2018-0308

nvd nist
Published: Jun 20, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability exists because the affected software insufficiently validates header values in Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow that could allow the attacker to execute arbitrary code or cause a DoS condition. This vulnerability affects the following if configured to use Cisco Fabric Services: Firepower 4100 Series Next-Generation Firewalls, Firepower 9300 Security Appliance, MDS 9000 Series Multilayer Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvd69954, CSCve02463, CSCve02785, CSCve02787, CSCve02804, CSCve04859.

Affected (12)

5 products
Nexus 7000 Firmware
Nexus 5000 Firmware
Firepower 9000 Firmware
Nexus 9000 Firmware
Unified Computing System Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 7.3(2)d1(0.49)
Version 8.0(1)
Version 8.1(0.112)s0
Running on/withPlatform Versions
Cisco
Nexus 7000
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 7.0(0)hsk(0.357)
Version 7.3(0)d1(0.98)
Version 8.1(0.2)s0
Running on/withPlatform Versions
Cisco
Nexus 5000
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version r211
Version r231
Running on/withPlatform Versions
Cisco
Firepower 9000
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 8.1(0)bd(0.20)
Version 8.1(1)s4
Running on/withPlatform Versions
Cisco
Nexus 9000
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.1(3a)a
Version 7.0(0)hsk(0.357)
Running on/withPlatform Versions
Cisco
Unified Computing System
All versions

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.