Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
BID:49472
Info
Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
| Bugtraq ID: | 49472 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2011 12:00AM |
| Updated: | Sep 06 2011 12:00AM |
| Credit: | SecureState and Core Security |
| Vulnerable: |
Cisco NX-OS 5.0 Cisco NX-OS 4.2(3) Cisco NX-OS 4.1(4) Cisco NX-OS 4.1(3)N2(1a) Cisco NX-OS 4.0(1a)N2(1) Cisco NX-OS 0 |
| Not Vulnerable: | |
Discussion
Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
Cisco NX-OS is prone to a heap memory corruption vulnerability.
An Attacker can exploit this issue to gain administrative access to the device running the operating system. Failed exploit attempts will result in a denial-of-service condition.
This issue being tracked by Cisco Bug ID CSCtf08873
Cisco NX-OS is prone to a heap memory corruption vulnerability.
An Attacker can exploit this issue to gain administrative access to the device running the operating system. Failed exploit attempts will result in a denial-of-service condition.
This issue being tracked by Cisco Bug ID CSCtf08873
Exploit / POC
Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]..
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]..
References
Cisco NX-OS CDP Packety Remote Heap Memory Corruption Vulnerability
References:
References:
- Cisco Homepage (Cisco)
- Cisco NX-OS CDP Remote Exploit (CORE Security)
- Metasploit module for imitating Cisco devices (SecureState)