The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00487.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Nexus 3016
Subscribe
Nexus 3048
Subscribe
Nexus 3064
Subscribe
Nexus 3132q
Subscribe
Nexus 3164q
Subscribe
Nexus 3172
Subscribe
Nexus 3524
Subscribe
Nexus 3548
Subscribe
Nexus 5010
Subscribe
Nexus 5020
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5624q
Subscribe
Nexus 5648q
Subscribe
Nexus 5672up
Subscribe
Nexus 5696q
Subscribe
Nexus 6001
Subscribe
Nexus 6004
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 9332pq
Subscribe
Nexus 9336pq Aci Spine
Subscribe
Nexus 9372px
Subscribe
Nexus 9372tx
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-0671 | The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-06T04:17:32.564Z
Reserved: 2015-01-07T00:00:00
Link: CVE-2015-0658
No data.
Status : Deferred
Published: 2015-03-28T01:59:49.210
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-0658
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD