CVE Feed

    Dashboard / CVE / CVE-2019-1901

    CVE-2019-1901

    A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode if they are running a Cisco Nexus 9000 Series ACI Mode Switch Software release prior to 13.2(7f) or any 14.x release.

    Published:Jul 31, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 31, 2019
    EPSS Score:0.00159
    CVSS Score:8.8

    Affected Products

    Vendor
    Cisco
    Product
    Nexus 93108tc-ex
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx
    Vendor
    Cisco
    Product
    Nexus 93120tx
    Vendor
    Cisco
    Product
    Nexus 93128tx
    Vendor
    Cisco
    Product
    Nexus 93180lc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx
    Vendor
    Cisco
    Product
    Nexus 93240yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9332c
    Vendor
    Cisco
    Product
    Nexus 9332pq
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2
    Vendor
    Cisco
    Product
    Nexus 9336pq
    Vendor
    Cisco
    Product
    Nexus 9348gc-fxp
    Vendor
    Cisco
    Product
    Nexus 9364c
    Vendor
    Cisco
    Product
    Nexus 9372px
    Vendor
    Cisco
    Product
    Nexus 9372px-e
    Vendor
    Cisco
    Product
    Nexus 9372tx
    Vendor
    Cisco
    Product
    Nexus 9372tx-e
    Vendor
    Cisco
    Product
    Nexus 9396px
    Vendor
    Cisco
    Product
    Nexus 9396tx
    Vendor
    Cisco
    Product
    Nexus 9504
    Vendor
    Cisco
    Product
    Nexus 9508
    Vendor
    Cisco
    Product
    Nexus 9516
    Vendor
    Cisco
    Product
    Nx-os

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High