7.8

CVE-2015-6260

Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zyxel ≫ Gs1900-10hp Firmware Version < 2.50\(aazi.0\)c0
   Cisco ≫ Nexus 5548p Version -
   Cisco ≫ Nexus 5548up Version -
   Cisco ≫ Nexus 5596t Version -
   Cisco ≫ Nexus 5596up Version -
   Cisco ≫ Nexus 56128p Version -
   Cisco ≫ Nexus 5624q Version -
   Cisco ≫ Nexus 5648q Version -
   Cisco ≫ Nexus 5672up Version -
   Cisco ≫ Nexus 5696q Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-n5ksnmp
Vendor Advisory
http://www.securitytracker.com/id/1035158