CVE-2015-4296
published 2015-08-19CVE-2015-4296: Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attackers to cause a denial of service (Java process restart) via…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.81%
76.4th percentile
Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attackers to cause a denial of service (Java process restart) via crafted connections to the Java application, aka Bug ID CSCut87006.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 3000 Nexus Data Broker Denial of Service Vulnerability
vendor_cisco·2015-08-12·CVSS 5.0
CVE-2015-4296 [MEDIUM] CWE-399 Cisco Nexus 3000 Nexus Data Broker Denial of Service Vulnerability
Cisco Nexus 3000 Nexus Data Broker Denial of Service Vulnerability
A vulnerability in the Nexus Data Broker (NDB) in Cisco Nexus 3000 Series Switches could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition.
The vulnerability is in handling incoming connections to the Java application. An attacker could exploit this vulnerability by sending crafted Java connections to the NDB. An exploit could allow the attacker to cause the Java process to restart, causing a partial DoS condition on the device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, the attacker would need to send crafted Java connections to a targeted device, making exploitation more difficult in environments that restrict networ
GHSA
GHSA-972w-6gc7-5c88: Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6
ghsa_unreviewed·2022-05-17
CVE-2015-4296 [MEDIUM] GHSA-972w-6gc7-5c88: Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6
Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attackers to cause a denial of service (Java process restart) via crafted connections to the Java application, aka Bug ID CSCut87006.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-19
Published