ID

VAR-201508-0493


CVE

CVE-2015-4324


TITLE

plural Cisco Nexus Run on device Cisco NX-OS Vulnerable to buffer overflow

Trust: 0.8

sources: JVNDB: JVNDB-2015-004364

DESCRIPTION

Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908. Vendors have confirmed this vulnerability Bug ID CSCuv69713 , CSCuv69717 , CSCuv69723 , CSCuv69732 ,and CSCuv48908 It is released as.A malformed format that was incorrectly handled by a third party when allocating memory IGMPv3 Service disruption via packets (IGMP Restart process ) There is a possibility of being put into a state. Cisco NX-OS Software is a data center-oriented operating system from Cisco. A denial of service vulnerability exists in Cisco NX-OS Software. An attacker could exploit the vulnerability to cause a denial of service and denial of service to legitimate users. This issue is being tracked by Cisco Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732 and CSCuv48908. and MDS 9000 devices are a set of operating systems run on Nexus 4000 series switch devices and MDS 9000 series fiber switch devices from Cisco

Trust: 2.52

sources: NVD: CVE-2015-4324 // JVNDB: JVNDB-2015-004364 // CNVD: CNVD-2015-05696 // BID: 76372 // VULHUB: VHN-82285

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-05696

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion:7.2\(0\)n1\(0.1\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:7.3\(0\)zn\(0.81\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:4.1\(2\)e1\(1c\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:4.1(2)e1(1c) (cisco nexus 4000 series )

Trust: 0.8

vendor:ciscomodel:nx-osscope:eqversion:7.2(0)n1(0.1) (cisco nexus 7000 series )

Trust: 0.8

vendor:ciscomodel:nx-osscope:eqversion:7.3(0)zn(0.81) (cisco nexus 3000 series /9000 series /1000v switch for vmware vsphere)

Trust: 0.8

vendor:ciscomodel:nx-os softwarescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2015-05696 // JVNDB: JVNDB-2015-004364 // CNNVD: CNNVD-201508-358 // NVD: CVE-2015-4324

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4324
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4324
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-05696
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201508-358
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82285
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4324
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-05696
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-82285
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-05696 // VULHUB: VHN-82285 // JVNDB: JVNDB-2015-004364 // CNNVD: CNNVD-201508-358 // NVD: CVE-2015-4324

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-82285 // JVNDB: JVNDB-2015-004364 // NVD: CVE-2015-4324

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201508-358

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201508-358

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004364

PATCH

title:40470url:http://tools.cisco.com/security/center/viewAlert.x?alertId=40470

Trust: 0.8

title:Patch for Cisco NX-OS Software Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/63139

Trust: 0.6

sources: CNVD: CNVD-2015-05696 // JVNDB: JVNDB-2015-004364

EXTERNAL IDS

db:NVDid:CVE-2015-4324

Trust: 3.4

db:BIDid:76372

Trust: 2.6

db:SECTRACKid:1033327

Trust: 1.1

db:JVNDBid:JVNDB-2015-004364

Trust: 0.8

db:CNNVDid:CNNVD-201508-358

Trust: 0.7

db:CNVDid:CNVD-2015-05696

Trust: 0.6

db:VULHUBid:VHN-82285

Trust: 0.1

sources: CNVD: CNVD-2015-05696 // VULHUB: VHN-82285 // BID: 76372 // JVNDB: JVNDB-2015-004364 // CNNVD: CNNVD-201508-358 // NVD: CVE-2015-4324

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=40470

Trust: 2.6

url:http://www.securityfocus.com/bid/76372

Trust: 1.7

url:http://www.securitytracker.com/id/1033327

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4324

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4324

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2015-05696 // VULHUB: VHN-82285 // BID: 76372 // JVNDB: JVNDB-2015-004364 // CNNVD: CNNVD-201508-358 // NVD: CVE-2015-4324

CREDITS

Cisco

Trust: 0.9

sources: BID: 76372 // CNNVD: CNNVD-201508-358

SOURCES

db:CNVDid:CNVD-2015-05696
db:VULHUBid:VHN-82285
db:BIDid:76372
db:JVNDBid:JVNDB-2015-004364
db:CNNVDid:CNNVD-201508-358
db:NVDid:CVE-2015-4324

LAST UPDATE DATE

2024-11-23T22:49:21.820000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-05696date:2015-08-27T00:00:00
db:VULHUBid:VHN-82285date:2017-01-04T00:00:00
db:BIDid:76372date:2015-08-17T00:00:00
db:JVNDBid:JVNDB-2015-004364date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-358date:2015-08-20T00:00:00
db:NVDid:CVE-2015-4324date:2024-11-21T02:30:50.107

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-05696date:2015-08-27T00:00:00
db:VULHUBid:VHN-82285date:2015-08-19T00:00:00
db:BIDid:76372date:2015-08-17T00:00:00
db:JVNDBid:JVNDB-2015-004364date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-358date:2015-08-19T00:00:00
db:NVDid:CVE-2015-4324date:2015-08-19T15:59:06.837