CVE-2017-3879
published 2017-03-17CVE-2017-3879: A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an…
PriorityP431medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
2.95%
85.7th percentile
A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCuy25824. Known Affected Releases: 7.0(3)I3(1) 8.3(0)CV(0.342) 8.3(0)CV(0.345). Known Fixed Releases: 8.3(0)CV(0.362) 8.0(1) 7.0(3)IED5(0.19) 7.0(3)IED5(0) 7.0(3)I4(1) 7.0(3)I4(0.8) 7.0(3)I2(2e) 7.0(3)F1(1.22) 7.0(3)F1(1) 7.0(3)F1(0.230).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_9000_series_switches | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88f9-c76f-fhv6: A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow a
ghsa_unreviewed·2022-05-17
CVE-2017-3879 [MEDIUM] CWE-119 GHSA-88f9-c76f-fhv6: A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow a
A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt. Affected Products: This vulnerability affects Cisco Nexus 9000 Series Switches that are running Cisco NX-OS Software and are configured to allow remote Telnet connections to the device. More Information: CSCuy25824. Known Affected Releases: 7.0(3)I3(1) 8.3(0)CV(0.342) 8.3(0)CV(0.345). Known Fixed Releases: 8.3(0)CV(0.362) 8.0(1) 7.0(3)IED5(0.19) 7.0(3)IED5(0) 7.0(3)I4(1) 7
Cisco
Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
vendor_cisco·2017-03-15·CVSS 5.3
CVE-2017-3879 [MEDIUM] CWE-119 Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
A vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt.
The vulnerability is due to improper handling of failed authentication during login. An attacker could exploit this vulnerability by attempting to log in remotely to the device. An exploit could allow the attacker to cause a login process to terminate unexpectedly.
There are no workarounds that address this vul
Cisco
Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3879 Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
CVE-2017-3879: Cisco Nexus 9000 Series Switches Remote Login Denial of Service Vulnerability
A vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker could use either a Telnet or an SSH client for the remote login attempt. The vulnerability is due to improper handling of failed authentication during login. An attacker could exploit this vulnerability by attempting to log in remotely to the device. An exploit could allow the attacker to cause a login process to terminate unexpectedly. There are no
CVSS: 3.0
CWE: CWE-11
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96920http://www.securitytracker.com/id/1038046https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-nss1http://www.securityfocus.com/bid/96920http://www.securitytracker.com/id/1038046https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-nss1
2017-03-17
Published