ID

VAR-201310-0016


CVE

CVE-2012-4099


TITLE

Cisco NX-OS of BGP Service disruption in implementations (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-004653

DESCRIPTION

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065. The Cisco Nexus Series switches are data center switches. Adopt the Cisco Nexus OS operating system. Cisco NX-OS is prone to a denial-of-service vulnerability. This issue is being tracked by Cisco bug ID CSCtn13065. The vulnerability is caused by the program not properly filtering invalid AS path values

Trust: 2.52

sources: NVD: CVE-2012-4099 // JVNDB: JVNDB-2013-004653 // CNVD: CNVD-2013-13498 // BID: 62840 // VULHUB: VHN-57380

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13498

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:nx-osscope: - version: -

Trust: 0.8

vendor:ciscomodel:nx-os softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:nx-osscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-13498 // BID: 62840 // JVNDB: JVNDB-2013-004653 // CNNVD: CNNVD-201310-280 // NVD: CVE-2012-4099

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-4099
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-4099
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-13498
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201310-280
value: MEDIUM

Trust: 0.6

VULHUB: VHN-57380
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-4099
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-13498
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-57380
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-13498 // VULHUB: VHN-57380 // JVNDB: JVNDB-2013-004653 // CNNVD: CNNVD-201310-280 // NVD: CVE-2012-4099

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-57380 // JVNDB: JVNDB-2013-004653 // NVD: CVE-2012-4099

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-280

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201310-280

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004653

PATCH

title:Cisco NX-OS Software BGP Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4099

Trust: 0.8

title:Patch for Cisco NX-OS Software BGP Denial of Service Vulnerability (CNVD-2013-13498)url:https://www.cnvd.org.cn/patchInfo/show/40056

Trust: 0.6

sources: CNVD: CNVD-2013-13498 // JVNDB: JVNDB-2013-004653

EXTERNAL IDS

db:NVDid:CVE-2012-4099

Trust: 3.4

db:OSVDBid:98130

Trust: 1.1

db:BIDid:62840

Trust: 1.0

db:JVNDBid:JVNDB-2013-004653

Trust: 0.8

db:CNVDid:CNVD-2013-13498

Trust: 0.6

db:CISCOid:20131004 CISCO NX-OS SOFTWARE BGP DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:CNNVDid:CNNVD-201310-280

Trust: 0.6

db:VULHUBid:VHN-57380

Trust: 0.1

sources: CNVD: CNVD-2013-13498 // VULHUB: VHN-57380 // BID: 62840 // JVNDB: JVNDB-2013-004653 // CNNVD: CNNVD-201310-280 // NVD: CVE-2012-4099

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2012-4099

Trust: 2.6

url:http://osvdb.org/98130

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-4099

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-4099

Trust: 0.8

url:http://tools.cisco.com/support/bugtoolkit/search/getbugdetails.do?method=fetchbugdetails&bugid=csctn13065

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps9494/products_sub_category_home.html

Trust: 0.3

sources: CNVD: CNVD-2013-13498 // VULHUB: VHN-57380 // BID: 62840 // JVNDB: JVNDB-2013-004653 // CNNVD: CNNVD-201310-280 // NVD: CVE-2012-4099

CREDITS

Cisco

Trust: 0.3

sources: BID: 62840

SOURCES

db:CNVDid:CNVD-2013-13498
db:VULHUBid:VHN-57380
db:BIDid:62840
db:JVNDBid:JVNDB-2013-004653
db:CNNVDid:CNNVD-201310-280
db:NVDid:CVE-2012-4099

LAST UPDATE DATE

2024-08-14T14:28:01.227000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13498date:2013-10-10T00:00:00
db:VULHUBid:VHN-57380date:2016-09-22T00:00:00
db:BIDid:62840date:2013-10-04T00:00:00
db:JVNDBid:JVNDB-2013-004653date:2013-10-17T00:00:00
db:CNNVDid:CNNVD-201310-280date:2013-10-15T00:00:00
db:NVDid:CVE-2012-4099date:2016-09-22T14:35:02.833

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13498date:2013-10-10T00:00:00
db:VULHUBid:VHN-57380date:2013-10-14T00:00:00
db:BIDid:62840date:2013-10-04T00:00:00
db:JVNDBid:JVNDB-2013-004653date:2013-10-17T00:00:00
db:CNNVDid:CNNVD-201310-280date:2013-10-15T00:00:00
db:NVDid:CVE-2012-4099date:2013-10-14T03:34:55.010