Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-0395


A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.


Published

2018-10-17T19:29:00.303

Last Modified

2024-11-21T03:38:08.380

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

5.5

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os 6.0\(4\) Yes
Operating System cisco nx-os 6.1\(3\)s2 Yes
Hardware cisco nexus_7000_10-slot - No
Hardware cisco nexus_7000_18-slot - No
Hardware cisco nexus_7000_4-slot - No
Hardware cisco nexus_7000_9-slot - No
Hardware cisco nexus_7700_10-slot - No
Hardware cisco nexus_7700_18-slot - No
Hardware cisco nexus_7700_2-slot - No
Hardware cisco nexus_7700_6-slot - No
Operating System cisco firepower_extensible_operating_system r231 Yes
Operating System cisco nx-os r231 Yes
Hardware cisco firepower_9300 - No
Operating System cisco nx-os 12.3\(1e\) Yes
Hardware cisco firepower_9300 - No
Operating System cisco nx-os 3.2\(3d\)c Yes
Hardware cisco ucs - No

References