HIGH · 8.3

CVE-2013-1178

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and...

Vulnerability Description

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.

CVSS Score

8.3

HIGH

AV:A/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoNx-Os4.0
CiscoNexus 7000-
CiscoNexus 7000 10-Slot-
CiscoNexus 7000 18-Slot-
CiscoNexus 7000 9-Slot-
CiscoMds 9000All versions
CiscoNexus 5000-
CiscoNexus 5010-
CiscoNexus 5020-
CiscoNexus 5548P-
CiscoNexus 5548Up-
CiscoNexus 5596Up-
CiscoNexus 4001I-
CiscoNexus 3000All versions
CiscoNexus 3016Q-
CiscoNexus 3048-
CiscoNexus 3064T-
CiscoNexus 3064X-
CiscoNexus 3548-
CiscoNexus 1000V-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1178?

CVE-2013-1178 is a vulnerability with a CVSS score of 8.3 (HIGH). Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and...

How severe is CVE-2013-1178?

CVE-2013-1178 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1178?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 7000, Cisco Nexus 7000 10-Slot, Cisco Nexus 7000 18-Slot, Cisco Nexus 7000 9-Slot.