A vulnerability, which was classified as problematic, has been found in Cisco NX-OS (the affected version is unknown). Affected by this issue is an unknown function of the component SNMP. The manipulation with an unknown input leads to a denial of service vulnerability (Restart). Using CWE to declare the problem leads to CWE-404. Impacted is availability.
The weakness was shared 10/17/2018 as cisco-sa-20181017-nxos-snmp as confirmed advisory (Website). The advisory is available at tools.cisco.com. This vulnerability is handled as CVE-2018-0456 since 11/26/2017. The attack may be launched remotely. A single authentication is needed for exploitation. The technical details are unknown and an exploit is not available. The structure of the vulnerability defines a possible price range of USD $5k-$25k at the moment (estimation calculated on 10/18/2018).
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
CPE
CVSSv3
VulDB Meta Base Score: 4.3
VulDB Meta Temp Score: 4.3
VulDB Base Score:
4.3VulDB Temp Score:
4.3VulDB Vector:
🔒VulDB Reliability:
🔍CVSSv2
VulDB Base Score:
🔒VulDB Temp Score:
🔒VulDB Reliability:
🔍Exploiting
Class: Denial of service / Restart (
CWE-404)
Local: No
Remote: Yes
Availability: No
Price Prediction:
🔍Current Price Estimation:
🔒Threat Intelligence
Threat:
🔍Adversaries:
🔍Geopolitics:
🔍Economy:
🔍Predictions:
🔍Actions:
🔍Countermeasures
Recommended: no mitigation known
0-Day Time:
🔒Timeline
11/26/2017 CVE assigned10/17/2018 Advisory disclosed10/18/2018 VulDB entry created10/18/2018 VulDB last updateSources
Advisory:
cisco-sa-20181017-nxos-snmpStatus: Confirmed
CVE:
CVE-2018-0456 (
🔒)
Entry
Created: 10/18/2018
Complete:
🔍Lien vers l'article source