Vulnerability Description
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 6.1\(2\) |
| Cisco | Nexus 7000 | All versions |
| Cisco | Nexus 7700 | All versions |
| Cisco | Nexus 5010 | All versions |
| Cisco | Nexus 5020 | All versions |
| Cisco | Nexus 5548P | All versions |
| Cisco | Nexus 5548Up | All versions |
| Cisco | Nexus 5596T | All versions |
| Cisco | Nexus 5596Up | All versions |
| Cisco | Nexus 56128P | All versions |
| Cisco | Nexus 5624Q | All versions |
| Cisco | Nexus 5648Q | All versions |
| Cisco | Nexus 5672Up | All versions |
| Cisco | Nexus 5696Q | All versions |
| Cisco | Nexus 6001 | All versions |
| Cisco | Nexus 6004 | All versions |
| Cisco | Nexus 93120Tx | All versions |
| Cisco | Nexus 93128Tx | All versions |
| Cisco | Nexus 9332Pq | All versions |
| Cisco | Nexus 9336Pq Aci Spine | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=38062Vendor Advisory
- http://www.securitytracker.com/id/1031992
- http://tools.cisco.com/security/center/viewAlert.x?alertId=38062Vendor Advisory
- http://www.securitytracker.com/id/1031992
FAQ
What is CVE-2015-0658?
CVE-2015-0658 is a vulnerability with a CVSS score of 7.9 (HIGH). The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary command...
How severe is CVE-2015-0658?
CVE-2015-0658 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0658?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 7000, Cisco Nexus 7700, Cisco Nexus 5010, Cisco Nexus 5020.