VDB

CISCO-SA-NDB-DNSDOS-BYSCZOSU

CISCO-SA-NDB-DNSDOS-BYSCZOSU PUBLISHED CVSS 7.5 HIGH

A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of DNS requests to an affected device. A successful exploit could allow the attacker to cause the coredns service to stop working or cause the device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Cisco Nexus Dashboard

Timeline

  • Feb 15, 2023 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›