CVE-2018-0299
published 2018-06-21CVE-2018-0299: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated…
PriorityP335medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.11%
79.8th percentile
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg10442.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_4000_series_switch_simple_network_management_protocol_polling | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
vendor_cisco·2018-06-20·CVSS 7.7
CVE-2018-0299 [HIGH] CWE-20 Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) feature of the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory
Cisco
Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0299 Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
CVE-2018-0299: Cisco Nexus 4000 Series Switch Simple Network Management Protocol Polling Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) feature of the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvg10
GHSA
GHSA-hhjf-8rx4-9rp6: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authentic
ghsa_unreviewed·2022-05-13
CVE-2018-0299 [MEDIUM] CWE-20 GHSA-hhjf-8rx4-9rp6: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authentic
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific MIB. An attacker could exploit this vulnerability by sending a specific SNMP poll request to the targeted device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg10442.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-06-21
Published