漏洞标题
N/A
漏洞描述信息
Cisco NX-OS软件中Cisco Nexus 3000 Series和Cisco Nexus 9000 Series交换机在 standalone NX-OS模式下的 Intermediate System-to-Intermediate System(IS-IS)协议的一个漏洞可能导致未验证的相邻攻击者使IS-IS进程意外重启,导致受影响设备重新加载。
该漏洞是由于在解析入站IS-IS packets时对输入验证不足。攻击者可以通过向受影响设备发送构造的IS-IS packets来利用此漏洞。成功利用此漏洞可能导致攻击者由于IS-IS进程意外重启而创建拒绝服务(DoS)条件,导致受影响设备重新加载。注意:IS-IS协议是一种路由协议。要利用此漏洞,攻击者必须与受影响设备在同一层2相邻。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
输入验证不恰当
漏洞标题
N/A
漏洞描述信息
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the unexpected restart of the IS-IS process, which could cause the affected device to reload. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2 adjacent to the affected device.
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
在缓冲区结束位置之后访问内存
漏洞标题
Cisco 多款产品输入验证错误漏洞
漏洞描述信息
Cisco NX-OS Software等都是美国思科(Cisco)公司的产品。Cisco NX-OS Software是一套交换机使用的数据中心级操作系统软件。Cisco Nexus 3000 Series Switches是一款3000系列交换机。Cisco Nexus 9000 Series Switches是一款9000系列交换机。 Cisco 多款产品存在安全漏洞,该漏洞源于IS-IS协议存在安全漏洞。攻击者可利用该漏洞通过发送IS-IS数据包来导致系统拒绝服务(DoS)。以下产品及版本受到影响
CVSS信息
N/A
漏洞类别
输入验证错误