漏洞信息详情

Cisco NX-OS Software和Cisco FXOS Software 输入验证漏洞

漏洞简介

Cisco NX-OS Software和Cisco FXOS Software都是美国思科(Cisco)公司的产品。Cisco NX-OS Software是一套交换机使用的数据中心级操作系统软件。Cisco FXOS Software是一套运行在思科安全设备中的防火墙软件。

Cisco FXOS Software和Cisco NX-OS Software中的轻量目录访问协议(LDAP)功能的实现存在输入验证漏洞,该漏洞源于程序错误地解析了LDAP数据包。远程攻击者可通过发送由基本编码规则(BER)构建的LDAP数据包利用该漏洞重新加载受影响设备,造成拒绝服务。以下产品受到影响:Cisco Firepower 4100 Series Next-Generation Firewalls;Firepower 9300 Security Appliance;MDS 9000 Series Multilayer Switches;Nexus 3000 Series Switches;Nexus 3500 Platform Switches;Nexus 7000 Series Switches;Nexus 7700 Series Switches;Nexus 9000 Series Switches in standalone NX-OS mode;UCS 6200 Series Fabric Interconnects;UCS 6300 Series Fabric Interconnects。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxosldap

参考网址

来源:CISCO

链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxosldap

来源:BID

链接:http://www.securityfocus.com/bid/107394

来源:www.nsfocus.net

链接:http://www.nsfocus.net/vulndb/42896

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-1597

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Cisco-NX-OS-Nexus-multiple-vulnerabilities-28681

来源:tools.cisco.com

链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxosldap

受影响实体

    暂无


漏洞信息快速查询

相关漏洞

更多