Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1968


A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.


Published

2019-08-30T09:15:20.380

Last Modified

2024-11-21T04:37:47.520

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os 7.3 Yes
Operating System cisco nx-os 8.1 Yes
Operating System cisco nx-os 8.2 Yes
Operating System cisco nx-os 8.3 Yes
Hardware cisco mds_9000 - No
Hardware cisco mds_9100 - No
Hardware cisco mds_9140 - No
Hardware cisco mds_9200 - No
Hardware cisco mds_9500 - No
Hardware cisco mds_9700 - No
Operating System cisco nx-os 6.1\(2\)i2 Yes
Operating System cisco nx-os 6.1\(2\)i3 Yes
Operating System cisco nx-os 7.0\(3\)i4 Yes
Operating System cisco nx-os 7.0\(3\)i7 Yes
Operating System cisco nx-os 9.2 Yes
Hardware cisco nexus_3016 - No
Hardware cisco nexus_3048 - No
Hardware cisco nexus_3064 - No
Hardware cisco nexus_3064-t - No
Hardware cisco nexus_31108pc-v - No
Hardware cisco nexus_31108tc-v - No
Hardware cisco nexus_31128pq - No
Hardware cisco nexus_3132c-z - No
Hardware cisco nexus_3132q - No
Hardware cisco nexus_3132q-v - No
Hardware cisco nexus_3132q-xl - No
Hardware cisco nexus_3164q - No
Hardware cisco nexus_3172 - No
Hardware cisco nexus_3172pq-xl - No
Hardware cisco nexus_3172tq - No
Hardware cisco nexus_3172tq-32t - No
Hardware cisco nexus_3172tq-xl - No
Hardware cisco nexus_3232c - No
Hardware cisco nexus_3264c-e - No
Hardware cisco nexus_3264q - No
Hardware cisco nexus_3408-s - No
Hardware cisco nexus_34180yc - No
Hardware cisco nexus_3432d-s - No
Hardware cisco nexus_3464c - No
Hardware cisco nexus_9000v - No
Hardware cisco nexus_92160yc-x - No
Hardware cisco nexus_92300yc - No
Hardware cisco nexus_92304qc - No
Hardware cisco nexus_92348gc-x - No
Hardware cisco nexus_9236c - No
Hardware cisco nexus_9272q - No
Hardware cisco nexus_93108tc-ex - No
Hardware cisco nexus_93108tc-fx - No
Hardware cisco nexus_93120tx - No
Hardware cisco nexus_93128tx - No
Hardware cisco nexus_93180lc-ex - No
Hardware cisco nexus_93180yc-ex - No
Hardware cisco nexus_93180yc-fx - No
Hardware cisco nexus_93216tc-fx2 - No
Hardware cisco nexus_93240yc-fx2 - No
Hardware cisco nexus_9332c - No
Hardware cisco nexus_9332pq - No
Hardware cisco nexus_93360yc-fx2 - No
Hardware cisco nexus_9336c-fx2 - No
Hardware cisco nexus_9336pq_aci_spine - No
Hardware cisco nexus_9348gc-fxp - No
Hardware cisco nexus_9364c - No
Hardware cisco nexus_9372px - No
Hardware cisco nexus_9372px-e - No
Hardware cisco nexus_9372tx - No
Hardware cisco nexus_9372tx-e - No
Hardware cisco nexus_9396px - No
Hardware cisco nexus_9396tx - No
Operating System cisco nx-os 6.0\(2\)a8 Yes
Operating System cisco nx-os 7.0\(3\)i7 Yes
Operating System cisco nx-os 9.2 Yes
Hardware cisco nexus_3524 - No
Hardware cisco nexus_3524-x - No
Hardware cisco nexus_3524-xl - No
Hardware cisco nexus_3548 - No
Hardware cisco nexus_3548-x - No
Hardware cisco nexus_3548-xl - No
Operating System cisco nx-os 7.0\(3\)f Yes
Operating System cisco nx-os 9.2 Yes
Hardware cisco nexus_36180yc-r - No
Hardware cisco nexus_3636c-r - No
Hardware cisco nexus_9504 - No
Hardware cisco nexus_9508 - No
Hardware cisco nexus_9516 - No
Operating System cisco nx-os 7.1 Yes
Operating System cisco nx-os 7.2 Yes
Operating System cisco nx-os 7.3 Yes
Hardware cisco nexus_5548p - No
Hardware cisco nexus_5548up - No
Hardware cisco nexus_5596t - No
Hardware cisco nexus_5596up - No
Hardware cisco nexus_56128p - No
Hardware cisco nexus_5624q - No
Hardware cisco nexus_5648q - No
Hardware cisco nexus_5672up - No
Hardware cisco nexus_5696q - No
Hardware cisco nexus_6001 - No
Hardware cisco nexus_6004 - No
Operating System cisco nx-os 7.2 Yes
Operating System cisco nx-os 7.3 Yes
Operating System cisco nx-os 8.0 Yes
Operating System cisco nx-os 8.1 Yes
Operating System cisco nx-os 8.2 Yes
Operating System cisco nx-os 8.3 Yes
Hardware cisco nexus_7000 - No
Hardware cisco nexus_7000_10-slot - No
Hardware cisco nexus_7000_18-slot - No
Hardware cisco nexus_7000_4-slot - No
Hardware cisco nexus_7000_9-slot - No
Hardware cisco nexus_7700 - No
Hardware cisco nexus_7700_10-slot - No
Hardware cisco nexus_7700_18-slot - No
Hardware cisco nexus_7700_2-slot - No
Hardware cisco nexus_7700_6-slot - No

References