Rewterz
Rewterz Threat Advisory – CVE-2019-11085 – Linux Kernel Intel i915 Graphics Driver Privilege Escalation Vulnerability
May 17, 2019
Rewterz
Rewterz Threat Advisory – CVE-2019-11634 – Citrix Multiple Products Security Bypass Vulnerability
May 21, 2019

Rewterz Threat Advisory – CVE-2019-1858 – Cisco Multiple Products FXOS / NX-OS SNMP Packet Processing Denial of Service Vulnerability

Severity

Medium

Analysis Summary

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this vulnerability by sending multiple crafted SNMP packets to an affected device. A successful exploit could allow the attacker to cause the SNMP application to leak system memory because of an improperly handled error condition during packet processing. Over time, this memory leak could cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition.

Impact

Denial of Service

Affected Vendors

Cisco

Affected Products

  • Cisco Firepower 4100 Series
  • Cisco Firepower 9300 Security Appliances
  • Cisco MDS 9000 Series Multilayer Switches
  • Cisco Nexus 1000V Switch for Microsoft Hyper-V
  • Cisco Nexus 1000V Switch for VMware vSphere
  • Cisco Nexus 3000 Series Switches
  • Cisco Nexus 3500 Platform Switches
  • Cisco Nexus 5500 Platform Switches
  • Cisco Nexus 5600 Platform Switches
  • Cisco Nexus 6000 Series Switches
  • Cisco Nexus 7000 Series Switches
  • Cisco Nexus 7700 Series Switches
  • Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode
  • Cisco Nexus 9000 Series Switches in standalone NX-OS mode
  • Cisco Nexus 9500 R-Series Switching Platform

Remediation

Vendor has released updates/patches for the following products.