cbcvebase.
CVE-2018-0395
published 2018-10-17

CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated…

PriorityP423medium5.3CVSS 3.0
AVAACHPRNUINSUCNINAH
EPSS
0.86%
54.4th percentile
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscocisco_nx-os_software>= unspecified < 6.2(1)6.2(1)
ciscofirepower_4100_series_next-generation_firewalls>= unspecified < <2.3.1.58<2.3.1.58
ciscofirepower_extensible_operating_system
ciscofxos_and_nx-os
cisconx-os
cisconx-os
cisconx-os
cisconx-os
cisconx-os

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.