HIGH · 8.8

CVE-2019-1901

A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated ...

Vulnerability Description

A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode if they are running a Cisco Nexus 9000 Series ACI Mode Switch Software release prior to 13.2(7f) or any 14.x release.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoNx-Os< 13.2\(7f\)
CiscoNexus 93108Tc-Ex-
CiscoNexus 93108Tc-Fx-
CiscoNexus 93120Tx-
CiscoNexus 93128Tx-
CiscoNexus 93180Lc-Ex-
CiscoNexus 93180Yc-Ex-
CiscoNexus 93180Yc-Fx-
CiscoNexus 9332Pq-
CiscoNexus 9336C-Fx2-
CiscoNexus 9336Pq-
CiscoNexus 9348Gc-Fxp-
CiscoNexus 9364C-
CiscoNexus 9372Px-
CiscoNexus 9372Px-E-
CiscoNexus 9372Tx-
CiscoNexus 9372Tx-E-
CiscoNexus 9396Px-
CiscoNexus 9396Tx-
CiscoNexus 9504-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1901?

CVE-2019-1901 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated ...

How severe is CVE-2019-1901?

CVE-2019-1901 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1901?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 93108Tc-Ex, Cisco Nexus 93108Tc-Fx, Cisco Nexus 93120Tx, Cisco Nexus 93128Tx.