Authentication Vulnerability in Cisco Firepower and NX-OS Systems
CVE-2017-3883
8.6HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 19 October 2017
Summary
An authentication vulnerability exists in the AAA implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software, which may allow unauthenticated remote attackers to cause impacted devices to reload. This issue is triggered when a high volume of login attempts prevents the NX-OS System Manager from receiving keepalive messages, potentially leading to low system memory and unexpected restarts of the AAA process. Attackers may exploit this issue by executing a brute-force login attack against devices configured with AAA security services, resulting in device reloads.
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved