CVE-2018-0395
published 2018-10-17CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated…
PriorityP423medium5.3CVSS 3.0
AVAACHPRNUINSUCNINAH
EPSS
0.86%
54.4th percentile
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | >= unspecified < 6.2(1) | 6.2(1) |
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < <2.3.1.58 | <2.3.1.58 |
| cisco | firepower_extensible_operating_system | — | — |
| cisco | fxos_and_nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wmx-fc2q-p8g5: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthentic
ghsa_unreviewed·2022-05-13
CVE-2018-0395 [MEDIUM] CWE-20 GHSA-3wmx-fc2q-p8g5: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthentic
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.
Cisco
Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·2018-10-17·CVSS 8.8
CVE-2018-0395 [HIGH] CWE-20 Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads.
The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulner
Cisco
Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0395 Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
CVE-2018-0395: Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105674http://www.securitytracker.com/id/1041919https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-fxnx-os-doshttp://www.securityfocus.com/bid/105674http://www.securitytracker.com/id/1041919https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-fxnx-os-dos
2018-10-17
Published