7.6

CVE-2014-3261

Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Cg-os Version cg4
Cisco ≫ Cgr 1120 Version -
Cisco ≫ Cgr 1240 Version -
Cisco ≫ Nx-os Version 5.2
Cisco ≫ Nexus 7000 Version -
Cisco ≫ Nexus 7000 10-slot Version -
Cisco ≫ Nexus 7000 18-slot Version -
Cisco ≫ Nexus 7000 9-slot Version -
Cisco ≫ Nx-os Version -
Cisco ≫ Nx-os Version 5.0
Cisco ≫ Nexus 3016q Version -
Cisco ≫ Nexus 3048 Version -
Cisco ≫ Nexus 3064t Version -
Cisco ≫ Nexus 3064x Version -
Cisco ≫ Nexus 3548 Version -
Cisco ≫ Nx-os Version 5.0
Cisco ≫ Nx-os Version 5.1
Cisco ≫ Nexus 5000 Version -
Cisco ≫ Nexus 5010 Version -
Cisco ≫ Nexus 5010p Switch Version -
Cisco ≫ Nexus 5020 Version -
Cisco ≫ Nexus 5020p Switch Version -
Cisco ≫ Nexus 5548p Version -
Cisco ≫ Nexus 5548up Version -
Cisco ≫ Nexus 5596up Version -
Cisco ≫ Nexus 4001i Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.782
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140521-nxos
Vendor Advisory