ID

VAR-201510-0004


CVE

CVE-2015-6308


TITLE

Cisco N3K Runs on the device Cisco NX-OS Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-005051

DESCRIPTION

Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684. Cisco N3K Runs on the device Cisco NX-OS There is a service disruption ( Temporary SNMP Stop ) There are vulnerabilities that are put into a state. The Cisco Nexus Series switches are data center switches. Adopt the Cisco Nexus OS operating system. An attacker can exploit this issue to cause a partial denial of service (DoS) condition to the SNMP service running on the device. This issue is being tracked by Cisco bug ID CSCuw36684. A security vulnerability exists in Cisco NX-OS 6.0(2)U6(0.46) release on N3K devices

Trust: 2.61

sources: NVD: CVE-2015-6308 // JVNDB: JVNDB-2015-005051 // CNVD: CNVD-2015-06451 // BID: 76913 // VULHUB: VHN-84269 // VULMON: CVE-2015-6308

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-06451

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion:6.0\(2\)u6\(0.46\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:for nexus 3000 series 6.0(2)u6(0.46)

Trust: 0.8

vendor:ciscomodel:nx-os 6.0 u6scope: - version: -

Trust: 0.6

vendor:ciscomodel:nx-os software for nexus series 6.0 u6scope:eqversion:3000

Trust: 0.3

sources: CNVD: CNVD-2015-06451 // BID: 76913 // JVNDB: JVNDB-2015-005051 // CNNVD: CNNVD-201510-011 // NVD: CVE-2015-6308

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6308
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6308
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-06451
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201510-011
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84269
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-6308
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6308
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2015-06451
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-84269
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-06451 // VULHUB: VHN-84269 // VULMON: CVE-2015-6308 // JVNDB: JVNDB-2015-005051 // CNNVD: CNNVD-201510-011 // NVD: CVE-2015-6308

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-84269 // JVNDB: JVNDB-2015-005051 // NVD: CVE-2015-6308

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201510-011

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201510-011

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005051

PATCH

title:41240url:http://tools.cisco.com/security/center/viewAlert.x?alertId=41240

Trust: 0.8

title:Cisco Nexus 3000 Series NX-OS SNMP Service Stop Responding Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/65000

Trust: 0.6

title:Cisco: Cisco Nexus 3000 Series Switches SNMP Non-Existent OID Denial of Service Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=Cisco-SA-20150930-CVE-2015-6308

Trust: 0.1

sources: CNVD: CNVD-2015-06451 // VULMON: CVE-2015-6308 // JVNDB: JVNDB-2015-005051

EXTERNAL IDS

db:NVDid:CVE-2015-6308

Trust: 3.5

db:SECTRACKid:1033717

Trust: 1.2

db:JVNDBid:JVNDB-2015-005051

Trust: 0.8

db:CNNVDid:CNNVD-201510-011

Trust: 0.7

db:CNVDid:CNVD-2015-06451

Trust: 0.6

db:BIDid:76913

Trust: 0.4

db:VULHUBid:VHN-84269

Trust: 0.1

db:VULMONid:CVE-2015-6308

Trust: 0.1

sources: CNVD: CNVD-2015-06451 // VULHUB: VHN-84269 // VULMON: CVE-2015-6308 // BID: 76913 // JVNDB: JVNDB-2015-005051 // CNNVD: CNNVD-201510-011 // NVD: CVE-2015-6308

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=41240

Trust: 2.7

url:http://www.securitytracker.com/id/1033717

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6308

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6308

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps11541/index.html

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps9372/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://www.rapid7.com/db/vulnerabilities/cisco-nx-os-cisco-sa-20150930-cve-2015-6308

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20150930-cve-2015-6308

Trust: 0.1

sources: CNVD: CNVD-2015-06451 // VULHUB: VHN-84269 // VULMON: CVE-2015-6308 // BID: 76913 // JVNDB: JVNDB-2015-005051 // CNNVD: CNNVD-201510-011 // NVD: CVE-2015-6308

CREDITS

Cisco

Trust: 0.3

sources: BID: 76913

SOURCES

db:CNVDid:CNVD-2015-06451
db:VULHUBid:VHN-84269
db:VULMONid:CVE-2015-6308
db:BIDid:76913
db:JVNDBid:JVNDB-2015-005051
db:CNNVDid:CNNVD-201510-011
db:NVDid:CVE-2015-6308

LAST UPDATE DATE

2024-11-23T21:43:47.610000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-06451date:2015-10-13T00:00:00
db:VULHUBid:VHN-84269date:2017-01-04T00:00:00
db:VULMONid:CVE-2015-6308date:2017-01-04T00:00:00
db:BIDid:76913date:2015-09-30T00:00:00
db:JVNDBid:JVNDB-2015-005051date:2015-10-07T00:00:00
db:CNNVDid:CNNVD-201510-011date:2015-10-09T00:00:00
db:NVDid:CVE-2015-6308date:2024-11-21T02:34:44.910

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-06451date:2015-10-13T00:00:00
db:VULHUBid:VHN-84269date:2015-10-02T00:00:00
db:VULMONid:CVE-2015-6308date:2015-10-02T00:00:00
db:BIDid:76913date:2015-09-30T00:00:00
db:JVNDBid:JVNDB-2015-005051date:2015-10-07T00:00:00
db:CNNVDid:CNNVD-201510-011date:2015-10-09T00:00:00
db:NVDid:CVE-2015-6308date:2015-10-02T15:59:01.457