Vulnerability Description
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | < 6.0\(2\)u6\(7\) |
| Cisco | Nexus 3016 | - |
| Cisco | Nexus 3048 | - |
| Cisco | Nexus 31108Pc-V | - |
| Cisco | Nexus 31108Tc-V | - |
| Cisco | Nexus 31128Pq | - |
| Cisco | Nexus 3132Q | - |
| Cisco | Nexus 3132Q-V | - |
| Cisco | Nexus 3164Q | - |
| Cisco | Nexus 3172 | - |
| Cisco | Nexus 3232C | - |
| Cisco | Nexus 3264Q | - |
| Cisco | 5548P | - |
| Cisco | 5548Up | - |
| Cisco | 5596T | - |
| Cisco | 5596Up | - |
| Cisco | 56128P | - |
| Cisco | 5624Q | - |
| Cisco | 5648Q | - |
| Cisco | 5672Up | - |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/93417Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036950Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/93417Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036950Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-1454?
CVE-2016-1454 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) ...
How severe is CVE-2016-1454?
CVE-2016-1454 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1454?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 3016, Cisco Nexus 3048, Cisco Nexus 31108Pc-V, Cisco Nexus 31108Tc-V.