Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3883


A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.


Published

2017-10-19T08:29:00.950

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.6 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco firepower_extensible_operating_system ≤ 2.3 Yes
Hardware cisco firepower_4100 - No
Operating System cisco fxos 2.3 Yes
Hardware cisco firepower_9300 - No
Operating System cisco nx-os 5.2 Yes
Operating System cisco nx-os 6.2 Yes
Operating System cisco nx-os 6.3 Yes
Operating System cisco nx-os 7.3 Yes
Operating System cisco nx-os 8.1 Yes
Operating System cisco nx-os 8.2 Yes
Hardware cisco mds_9000 - No
Operating System cisco nx-os ≤ 4.1 Yes
Operating System cisco nx-os 5.2 Yes
Hardware cisco nexus_1000v - No
Hardware cisco nexus_1100v - No
Operating System cisco nx-os ≤ 6.0 Yes
Operating System cisco nx-os 7.0 Yes
Hardware cisco nexus_3000 - No
Hardware cisco nexus_3016 - No
Hardware cisco nexus_3016q - No
Hardware cisco nexus_3048 - No
Hardware cisco nexus_3064 - No
Hardware cisco nexus_3064t - No
Hardware cisco nexus_3064x - No
Operating System cisco nx-os 7.0\(3\)i3\(1\) Yes
Hardware cisco nexus_3500 - No
Hardware cisco nexus_3524 - No
Hardware cisco nexus_3548 - No
Operating System cisco nx-os ≤ 5.2 Yes
Hardware cisco nexus_2000 - No
Hardware cisco nexus_5000 - No
Hardware cisco nexus_5010 - No
Hardware cisco nexus_5010p_switch - No
Hardware cisco nexus_5500 - No
Hardware cisco nexus_5548p - No
Hardware cisco nexus_5548up - No
Hardware cisco nexus_5596t - No
Hardware cisco nexus_5596up - No
Hardware cisco nexus_5600 - No
Hardware cisco nexus_56128p - No
Hardware cisco nexus_5624q - No
Hardware cisco nexus_5648q - No
Hardware cisco nexus_5672up - No
Hardware cisco nexus_5696q - No
Hardware cisco nexus_6000 - No
Hardware cisco nexus_6001 - No
Hardware cisco nexus_6004 - No
Hardware cisco nexus_6004x - No
Operating System cisco nx-os 7.1\(0.1\) Yes
Hardware cisco nexus_7000 - No
Hardware cisco nexus_7000_10-slot - No
Hardware cisco nexus_7000_18-slot - No
Hardware cisco nexus_7000_9-slot - No
Hardware cisco nexus_7700 - No
Operating System cisco nx-os 6.1 Yes
Operating System cisco nx-os 7.0 Yes
Hardware cisco nexus_9000 - No
Operating System cisco nx-os 7.0 Yes
Hardware cisco 9500_r - No
Operating System cisco nx-os ≤ 2.2 Yes
Operating System cisco nx-os 2.5 Yes
Operating System cisco nx-os 3.0 Yes
Operating System cisco nx-os 3.1 Yes
Operating System cisco nx-os 3.2 Yes
Hardware cisco ucs_6100 - No
Hardware cisco ucs_6200 - No
Hardware cisco ucs_6300 - No

References