VDB

CVE-2019-1616

CVE-2019-1616 PUBLISHED CVSS 8.600000381469727 HIGH

A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow, resulting in process crashes and a DoS condition on the device. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25), 8.1(1b), 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5) Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22) and 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5). UCS 6200, 6300, and 6400 Fabric Interconnects are affected running software versions prior to 3.2(3j) and 4.0(2a).

EPSS 0.82% · 74.7th percentile

Risk Scores

CVSS 3.0
8.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.82%
74.7th percentile

Affected Products

VendorProductVersions
CiscoNexus 3600 Platform Switchesunspecified
CiscoNexus 7000 and 7700 Series Switchesunspecified, unspecified
CiscoMDS 9000 Series Multilayer Switchesunspecified, unspecified, *
CiscoNexus 9000 Series Switches in Standalone NX-OS Mode*, unspecified
CiscoNexus 3000 Series Switches*, unspecified
CiscoNexus 9500 R-Series Line Cards and Fabric Modules*
cisconx-os7.0\(3\)i5, *, *
CiscoUCS 6200, 6300, and 6400 Fabric Interconnectsunspecified, unspecified
CiscoNexus 3500 Platform Switchesunspecified, *

Timeline

  • Mar 6, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score

References

…and 7 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›