ID

VAR-201305-0151


CVE

CVE-2013-1211


TITLE

Cisco Nexus 1000V Run on Cisco NX-OS In VEM Vulnerabilities accessed by

Trust: 0.8

sources: JVNDB: JVNDB-2013-002853

DESCRIPTION

Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM access via (1) spoofed STUN packets or (2) a crafted VMware ESXi instance, aka Bug ID CSCud14832. Vendors have confirmed this vulnerability Bug ID CSCud14832 It is released as.By a third party (1) Camouflaged STUN Packet, or (2) Cleverly crafted VMware ESXi Through the instance VEM May be accessed. The Cisco Nexus Series switches are data center switches. Adopt the Cisco Nexus OS operating system. Remote attackers can exploit this issue to bypass authentication mechanism and gain unauthorized access to an affected device. This may aid in further attacks. This issue is being tracked by Cisco Bug ID CSCud14832. http://drupal.org/node/207891

Trust: 2.52

sources: NVD: CVE-2013-1211 // JVNDB: JVNDB-2013-002853 // CNVD: CNVD-2013-06432 // BID: 60222 // VULHUB: VHN-61213

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-06432

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:nx-osscope: - version: -

Trust: 1.4

vendor:ciscomodel:nexus 1000v switchscope: - version: -

Trust: 0.8

vendor:ciscomodel:nexusscope:eqversion:1000v

Trust: 0.6

vendor:ciscomodel:nexusscope:eqversion:1000v0

Trust: 0.3

sources: CNVD: CNVD-2013-06432 // BID: 60222 // JVNDB: JVNDB-2013-002853 // CNNVD: CNNVD-201305-608 // NVD: CVE-2013-1211

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1211
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-1211
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-06432
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201305-608
value: MEDIUM

Trust: 0.6

VULHUB: VHN-61213
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-1211
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-06432
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-61213
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-06432 // VULHUB: VHN-61213 // JVNDB: JVNDB-2013-002853 // CNNVD: CNNVD-201305-608 // NVD: CVE-2013-1211

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-61213 // JVNDB: JVNDB-2013-002853 // NVD: CVE-2013-1211

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201305-608

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201305-608

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002853

PATCH

title:Cisco Nexus 1000V Insufficient VSM/VEM Authenticationurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1211

Trust: 0.8

title:29469url:http://tools.cisco.com/security/center/viewAlert.x?alertId=29469

Trust: 0.8

title:Patch for Cisco Nexus 1000V Insufficient VSM/VEM Verification Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/34389

Trust: 0.6

sources: CNVD: CNVD-2013-06432 // JVNDB: JVNDB-2013-002853

EXTERNAL IDS

db:NVDid:CVE-2013-1211

Trust: 3.4

db:JVNDBid:JVNDB-2013-002853

Trust: 0.8

db:CNNVDid:CNNVD-201305-608

Trust: 0.7

db:CNVDid:CNVD-2013-06432

Trust: 0.6

db:CISCOid:20130528 CISCO NEXUS 1000V INSUFFICIENT VSM/VEM AUTHENTICATION

Trust: 0.6

db:BIDid:60222

Trust: 0.4

db:VULHUBid:VHN-61213

Trust: 0.1

sources: CNVD: CNVD-2013-06432 // VULHUB: VHN-61213 // BID: 60222 // JVNDB: JVNDB-2013-002853 // CNNVD: CNNVD-201305-608 // NVD: CVE-2013-1211

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-1211

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1211

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1211

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps9902/tsd_products_support_series_home.html

Trust: 0.3

sources: CNVD: CNVD-2013-06432 // VULHUB: VHN-61213 // BID: 60222 // JVNDB: JVNDB-2013-002853 // CNNVD: CNNVD-201305-608 // NVD: CVE-2013-1211

CREDITS

Felix 'FX' Lindner of Recurity Labs GmbH

Trust: 0.3

sources: BID: 60222

SOURCES

db:CNVDid:CNVD-2013-06432
db:VULHUBid:VHN-61213
db:BIDid:60222
db:JVNDBid:JVNDB-2013-002853
db:CNNVDid:CNNVD-201305-608
db:NVDid:CVE-2013-1211

LAST UPDATE DATE

2024-08-14T14:06:47.130000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-06432date:2013-05-31T00:00:00
db:VULHUBid:VHN-61213date:2013-05-30T00:00:00
db:BIDid:60222date:2013-05-31T07:14:00
db:JVNDBid:JVNDB-2013-002853date:2013-05-31T00:00:00
db:CNNVDid:CNNVD-201305-608date:2013-05-31T00:00:00
db:NVDid:CVE-2013-1211date:2013-05-30T13:43:37.373

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-06432date:2013-05-31T00:00:00
db:VULHUBid:VHN-61213date:2013-05-29T00:00:00
db:BIDid:60222date:2013-05-29T00:00:00
db:JVNDBid:JVNDB-2013-002853date:2013-05-31T00:00:00
db:CNNVDid:CNNVD-201305-608date:2013-05-30T00:00:00
db:NVDid:CVE-2013-1211date:2013-05-29T19:55:01.067