Authentication Vulnerability in Cisco Firepower and NX-OS Systems
CVE-2017-3883

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 October 2017

Summary

An authentication vulnerability exists in the AAA implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software, which may allow unauthenticated remote attackers to cause impacted devices to reload. This issue is triggered when a high volume of login attempts prevents the NX-OS System Manager from receiving keepalive messages, potentially leading to low system memory and unexpected restarts of the AAA process. Attackers may exploit this issue by executing a brute-force login attack against devices configured with AAA security services, resulting in device reloads.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.