A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Firepower 9300
Subscribe
Firepower Extensible Operating System
Subscribe
Nexus 7000 10-slot
Subscribe
Nexus 7000 18-slot
Subscribe
Nexus 7000 4-slot
Subscribe
Nexus 7000 9-slot
Subscribe
Nexus 7700 10-slot
Subscribe
Nexus 7700 18-slot
Subscribe
Nexus 7700 2-slot
Subscribe
Nexus 7700 6-slot
Subscribe
Nx-os
Subscribe
Ucs
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-1218 | A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 26 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-26T14:25:34.390Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0395
Updated: 2024-08-05T03:21:15.658Z
Status : Modified
Published: 2018-10-17T19:29:00.303
Modified: 2024-11-21T03:38:08.380
Link: CVE-2018-0395
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD