CVE-2011-0355
Summary
| CVE | CVE-2011-0355 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-17 18:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash) by sending an 802.1Q tagged packet over an access vEthernet port, aka Cisco Bug ID CSCtj17451. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | 1000v Virtual Ethernet Module Vem | 4.0\(4\) | sv1\(1\) | All | All |
| Application | Cisco | 1000v Virtual Ethernet Module Vem | 4.0\(4\) | sv1\(2\) | All | All |
| Application | Cisco | 1000v Virtual Ethernet Module Vem | 4.0\(4\) | sv1\(3a\) | All | All |
| Application | Cisco | 1000v Virtual Ethernet Module Vem | 4.0\(4\) | sv1\(3b\) | All | All |
| Application | Cisco | 1000v Virtual Ethernet Module Vem | 4.0\(4\) | sv1\(3\) | All | All |
| Application | Vmware | Esx | 4.0 | All | All | All |
| Application | Vmware | Esx | 4.1 | All | All | All |
| Application | Vmware | Esxi | 4.0 | All | All | All |
| Application | Vmware | Esxi | 4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware ESX/Cisco Nexus 1000V Packet Processing Bug Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Security Advisory SA43084 - Cisco Nexus 1000V Virtual Switch 802.1Q Tagged Packet Denial of Service - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Nexus 1000V VEM updates address denial of service in V | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Nexus 1000V Release Notes, Release 4.0(4) SV1(3c) [Cisco Nexus 1000V Series Switches] - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | |
| [Security-announce] VMSA-2011-0002 Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | |
| Cisco Nexus 1000V VEM Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| www.osvdb.org/70837 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.