ID

VAR-201903-0548


CVE

CVE-2019-1617


TITLE

Cisco NX-OS Software improper control of dynamically manipulated code resources vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-002431

DESCRIPTION

A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker could exploit this vulnerability by sending a stream of FCoE frames from an adjacent host to an affected device. An exploit could allow the attacker to cause packet amplification to occur, resulting in the saturation of interfaces and a DoS condition. Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I7(5) and 9.2(2). Cisco NX-OS The software is vulnerable to improper control of dynamically manipulated code resources.Service operation interruption (DoS) There is a possibility of being put into a state. Cisco Nexus 9000 Series Switches is a 9000 series switch of Cisco of the United States. Cisco NX-OS Software is a set of data center-level operating system software used by switches. An attacker can use this vulnerability to cause a denial of service. This issue is being tracked by Cisco bug ID CSCvk44504

Trust: 2.52

sources: NVD: CVE-2019-1617 // JVNDB: JVNDB-2019-002431 // CNVD: CNVD-2020-47606 // BID: 107336 // VULHUB: VHN-148289

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-47606

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:gteversion:9.2

Trust: 1.0

vendor:ciscomodel:nx-osscope:ltversion:9.2\(2\)

Trust: 1.0

vendor:ciscomodel:nx-osscope:ltversion:7.0\(3\)i7\(5\)

Trust: 1.0

vendor:ciscomodel:nx-osscope:gteversion:7.0\(3\)i5

Trust: 1.0

vendor:ciscomodel:nx-osscope:ltversion:7.0(3)i7(5)

Trust: 0.8

vendor:ciscomodel:nx-osscope:ltversion:9.2(2)

Trust: 0.8

vendor:ciscomodel:nexus series switches in standalone nx-os modescope:eqversion:9000

Trust: 0.6

vendor:ciscomodel:n9k-x9736c-fxscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c93180yc-fxscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c93180lc-exscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-x9732c-exscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c93180yc-exscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c9236cscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c9272qscope: - version: -

Trust: 0.6

vendor:ciscomodel:n9k-c92160yc-xscope: - version: -

Trust: 0.6

vendor:ciscomodel:nx-os 7.0 i7scope: - version: -

Trust: 0.6

vendor:ciscomodel:nx-os 7.0 i7scope:neversion: -

Trust: 0.6

vendor:ciscomodel:nx-osscope:eqversion:9.2

Trust: 0.3

vendor:ciscomodel:nx-os 7.0 i6scope: - version: -

Trust: 0.3

vendor:ciscomodel:nx-os 7.0 i5scope: - version: -

Trust: 0.3

vendor:ciscomodel:nx-os 7.0 i4scope: - version: -

Trust: 0.3

vendor:ciscomodel:nexus series switches in standalone nx-os modescope:eqversion:90000

Trust: 0.3

vendor:ciscomodel:nx-osscope:neversion:9.2(2)

Trust: 0.3

sources: CNVD: CNVD-2020-47606 // BID: 107336 // JVNDB: JVNDB-2019-002431 // NVD: CVE-2019-1617

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-1617
value: HIGH

Trust: 1.0

ykramarz@cisco.com: CVE-2019-1617
value: HIGH

Trust: 1.0

NVD: CVE-2019-1617
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-47606
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201903-164
value: HIGH

Trust: 0.6

VULHUB: VHN-148289
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-1617
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-47606
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-148289
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-1617
baseSeverity: HIGH
baseScore: 7.4
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 4.0
version: 3.0

Trust: 2.8

sources: CNVD: CNVD-2020-47606 // VULHUB: VHN-148289 // JVNDB: JVNDB-2019-002431 // CNNVD: CNNVD-201903-164 // NVD: CVE-2019-1617 // NVD: CVE-2019-1617

PROBLEMTYPE DATA

problemtype:CWE-913

Trust: 1.9

sources: VULHUB: VHN-148289 // JVNDB: JVNDB-2019-002431 // NVD: CVE-2019-1617

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201903-164

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201903-164

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-002431

PATCH

title:cisco-sa-20190306-nxos-npv-dosurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-npv-dos

Trust: 0.8

title:Patch for Cisco Nexus 9000 Series FCoE NPV Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/231505

Trust: 0.6

title:Cisco NX-OS Software Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89839

Trust: 0.6

sources: CNVD: CNVD-2020-47606 // JVNDB: JVNDB-2019-002431 // CNNVD: CNNVD-201903-164

EXTERNAL IDS

db:NVDid:CVE-2019-1617

Trust: 3.4

db:BIDid:107336

Trust: 2.0

db:JVNDBid:JVNDB-2019-002431

Trust: 0.8

db:CNNVDid:CNNVD-201903-164

Trust: 0.7

db:CNVDid:CNVD-2020-47606

Trust: 0.6

db:VULHUBid:VHN-148289

Trust: 0.1

sources: CNVD: CNVD-2020-47606 // VULHUB: VHN-148289 // BID: 107336 // JVNDB: JVNDB-2019-002431 // CNNVD: CNNVD-201903-164 // NVD: CVE-2019-1617

REFERENCES

url:http://www.securityfocus.com/bid/107336

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-1617

Trust: 2.0

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190306-nxos-npv-dos

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-1617

Trust: 0.8

url:https://vigilance.fr/vulnerability/cisco-nx-os-nexus-multiple-vulnerabilities-28681

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:https://bst.cloudapps.cisco.com/bugsearch/bug/cscvk44504

Trust: 0.3

sources: CNVD: CNVD-2020-47606 // VULHUB: VHN-148289 // BID: 107336 // JVNDB: JVNDB-2019-002431 // CNNVD: CNNVD-201903-164 // NVD: CVE-2019-1617

CREDITS

or through a Cisco authorized reseller or partner. In most cases this will be a maintenance upgrade to software that was previously purchased. Free security software updates do not entitle customers to a new software license, or otherwise using such software upgrades, accessing, customers agree to follow the terms of the Cisco software license: https://www.cisco.com/c/en/us/products/end-user-license-agreement.html Additionally, customers should consider that this advisory is part of a bundled publication. The following page provides a complete list of bundle advisories: Cisco?Event Response: March 2019 Cisco?FXOS and NX-OS Software Security Advisory Bundled Publication. In the following tables, refer to the Recommended Releases documents in the release notes for the device., the left column lists releases of Cisco?FXOS Software or Cisco?NX-OS Software. The center column indicates whether a release is affected by the vulnerability described in this advisory and the first release that includes the fix for this vulnerability. The right column indicates whether a release is affected by all the vulnerabilities described in this bundle and which release includes fixes for those vulnerabilities. Although the releases listed in the right column of each table include fixes for the vulnerabilities, the fix related to the Cisco NX-OS Software Image Signature Verification Vulnerability requires a BIOS upgrade as part of the software upgrade. Customers who are upgrading the software for any of the following products are advised to refer to this advisory for further details about the BIOS upgrade and affected product IDs and BIOS versions: Nexus 3000 Series Switches Nexus 9000 Series Fabric Switches in ACI mode Nexus 9000 Series Switches in standalone NX-OS mode Nexus 9500 R-Series Line Cards and Fabric Modules Nexus 9000 Series Switches in Standalone NX-OS Mode:?CSCvk44504 Cisco NX-OS Software Release First Fixed Release for This Vulnerability First Fixed Release for All Vulnerabilities Described in the Bundle?of Advisories Prior to 7.0(3)I4 Not vulnerable 7.0(3)I7(6) 7.0(3)I4 Not vulnerable 7.0(3)I7(6) 7.0(3)I5 7.0(3)I7(5) 7.0(3)I7(6) 7.0(3)I6 7.0(3)I7(5) 7.0(3)I7(6) 7.0(3)I7 7.0(3)I7(5) 7.0(3)I7(6) 9.2 9.2(2) 9.2(2) Additional Resources For help determining the best Cisco NX-OS Software release for a Cisco Nexus Switch, which are available from the Cisco Security Advisories and Alerts page, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers. Customers Without Service Contracts Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC: https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade. Fixed Releases Customers are advised to upgrade to an appropriate release as indicated in the applicable table in this section. To help ensure a complete upgrade solution, administrators can refer to the following Recommended Releases documents.?If a security advisory recommends a later release, or major revision upgrades. When considering software upgrades,Cisco has released free software updates that address the vulnerability described in this advisory. Customers may only install and expect support for software versions and feature sets for which they have purchased a license. By installing, Cisco recommends following the advisory guidance. Cisco MDS Series Switches Cisco Nexus 1000V for VMware Switch Cisco Nexus 3000 Series and 3500 Series Switches Cisco Nexus 5000 Series Switches Cisco Nexus 5500 Platform Switches Cisco Nexus 6000 Series Switches Cisco Nexus 7000 Series Switches Cisco Nexus 9000 Series Switches Cisco Nexus 9000 Series ACI-Mode Switches For help determining the best Cisco NX-OS Software release for Cisco UCS, to determine exposure and a complete upgrade solution. In all cases, procured from Cisco directly, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers may only download software for which they have a valid license, additional software feature sets, customers are advised to regularly consult the advisories for Cisco products, downloading

Trust: 0.6

sources: CNNVD: CNNVD-201903-164

SOURCES

db:CNVDid:CNVD-2020-47606
db:VULHUBid:VHN-148289
db:BIDid:107336
db:JVNDBid:JVNDB-2019-002431
db:CNNVDid:CNNVD-201903-164
db:NVDid:CVE-2019-1617

LAST UPDATE DATE

2024-11-23T22:12:08.586000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-47606date:2020-08-24T00:00:00
db:VULHUBid:VHN-148289date:2019-10-09T00:00:00
db:BIDid:107336date:2019-03-06T00:00:00
db:JVNDBid:JVNDB-2019-002431date:2019-04-09T00:00:00
db:CNNVDid:CNNVD-201903-164date:2019-10-17T00:00:00
db:NVDid:CVE-2019-1617date:2024-11-21T04:36:56.387

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-47606date:2019-08-26T00:00:00
db:VULHUBid:VHN-148289date:2019-03-11T00:00:00
db:BIDid:107336date:2019-03-06T00:00:00
db:JVNDBid:JVNDB-2019-002431date:2019-04-09T00:00:00
db:CNNVDid:CNNVD-201903-164date:2019-03-06T00:00:00
db:NVDid:CVE-2019-1617date:2019-03-11T21:29:01.027