MEDIUM · 6.5

CVE-2016-6457

A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) ...

Vulnerability Description

A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoApplication Policy Infrastructure Controller1.2\(2\)
CiscoNx-Os11.2\(2g\)
CiscoNexus 92160Yc-X-
CiscoNexus 92304Qc-
CiscoNexus 9236C-
CiscoNexus 9272Q-
CiscoNexus 93108Tc-Ex-
CiscoNexus 93120Tx-
CiscoNexus 93128Tx-
CiscoNexus 93180Yc-Ex-
CiscoNexus 9332Pq-
CiscoNexus 9336Pq Aci Spine-
CiscoNexus 9372Px-
CiscoNexus 9372Tx-
CiscoNexus 9396Px-
CiscoNexus 9396Tx-
CiscoNexus 9504-
CiscoNexus 9508-
CiscoNexus 9516-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6457?

CVE-2016-6457 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) ...

How severe is CVE-2016-6457?

CVE-2016-6457 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-6457?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Application Policy Infrastructure Controller, Cisco Nx-Os, Cisco Nexus 92160Yc-X, Cisco Nexus 92304Qc, Cisco Nexus 9236C.