CVE-2015-0658Improper Input Validation in Cisco Nx-os

Severity
7.9HIGHNVD
EPSS
0.5%
top 34.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMay 17

Description

The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.

CVSS vector

AV:A/AC:M/C:C/I:C/A:CExploitability: 5.5 | Impact: 10.0

Affected Packages1 packages

NVDcisco/nx-os68 versions+67

🔴Vulnerability Details

2
GHSA
GHSA-p8qc-7hcq-6crg: The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which al2022-05-17
CVEList
CVE-2015-0658: The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which al2015-03-28

📋Vendor Advisories

1
Cisco
Cisco NX-OS Software DHCP Options Command Injection Vulnerability2015-03-27
CVE-2015-0658 — Improper Input Validation in Cisco | cvebase