Vulnerability Description
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Policy Infrastructure Controller | 1.2\(2\) |
| Cisco | Nx-Os | 11.2\(2g\) |
| Cisco | Nexus 92160Yc-X | - |
| Cisco | Nexus 92304Qc | - |
| Cisco | Nexus 9236C | - |
| Cisco | Nexus 9272Q | - |
| Cisco | Nexus 93108Tc-Ex | - |
| Cisco | Nexus 93120Tx | - |
| Cisco | Nexus 93128Tx | - |
| Cisco | Nexus 93180Yc-Ex | - |
| Cisco | Nexus 9332Pq | - |
| Cisco | Nexus 9336Pq Aci Spine | - |
| Cisco | Nexus 9372Px | - |
| Cisco | Nexus 9372Tx | - |
| Cisco | Nexus 9396Px | - |
| Cisco | Nexus 9396Tx | - |
| Cisco | Nexus 9504 | - |
| Cisco | Nexus 9508 | - |
| Cisco | Nexus 9516 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94077Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037185Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2MitigationVendor Advisory
- http://www.securityfocus.com/bid/94077Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037185Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2MitigationVendor Advisory
FAQ
What is CVE-2016-6457?
CVE-2016-6457 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) ...
How severe is CVE-2016-6457?
CVE-2016-6457 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6457?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Application Policy Infrastructure Controller, Cisco Nx-Os, Cisco Nexus 92160Yc-X, Cisco Nexus 92304Qc, Cisco Nexus 9236C.