CVE-2015-4324
published 2015-08-19CVE-2015-4324: Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c)…
PriorityP427medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.13%
62.9th percentile
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mmx-4w74-g4x8: Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7
ghsa_unreviewed·2022-05-17
CVE-2015-4324 [MEDIUM] CWE-119 GHSA-4mmx-4w74-g4x8: Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Cisco
Cisco NX-OS Internet Group Management Protocol Denial of Service Vulnerability
vendor_cisco·2015-08-17·CVSS 6.1
CVE-2015-4324 [MEDIUM] CWE-119 Cisco NX-OS Internet Group Management Protocol Denial of Service Vulnerability
Cisco NX-OS Internet Group Management Protocol Denial of Service Vulnerability
A vulnerability in the Internet Group Management Protocol version 3 (IGMPv3) input packet processing of Cisco NX-OS could allow an unauthenticated, adjacent attacker to cause the IGMP process to restart due to a malformed IGMP packet, which could cause a denial of service (DoS) condition on the device.
The vulnerability is due to improper input validation when ensuring the memory allocated is large enough for the number of included sources in the IGMPv3 packet. An attacker could exploit this vulnerability by sending a crafted IGMPv3 packet to the targeted device. An exploit could allow the attacker to cause the IGMP process to restart due to a buffer overflow, which may cause a DoS condition.
Cisco has confir
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-19
Published