imPC@ndo IT

Tracker / CVE-2013-1178

CVE-2013-1178

High 8.3

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.

Affected products and versions

cisco cg-os
cisco cg-os · … → cg4
cisco connected_grid_router_1000
cisco mds_9000
cisco nexus_1000v
cisco nexus_3000
cisco nexus_3016q
cisco nexus_3048
cisco nexus_3064t
cisco nexus_3064x
cisco nexus_3548
cisco nexus_4001i
cisco nexus_5000
cisco nexus_5010
cisco nexus_5020
cisco nexus_5548p
cisco nexus_5548up
cisco nexus_5596up
cisco nexus_7000
cisco nexus_7000_10-slot
cisco nexus_7000_18-slot
cisco nexus_7000_9-slot
cisco nx-os
cisco nx-os · … → 4.1.\(2\)
cisco unified_computing_system_6120xp_fabric_interconnect
cisco unified_computing_system_6140xp_fabric_interconnect
cisco unified_computing_system_6248up_fabric_interconnect
cisco unified_computing_system_6296up_fabric_interconnect
cisco unified_computing_system_infrastructure_and_unified_computing_system_software
cisco unified_computing_system_infrastructure_and_unified_computing_system_software · … → 2.0\(1x\)

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References