A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Mds 9132t
Subscribe
Mds 9148s
Subscribe
Mds 9148t
Subscribe
Mds 9216
Subscribe
Mds 9216a
Subscribe
Mds 9216i
Subscribe
Mds 9222i
Subscribe
Mds 9506
Subscribe
Mds 9509
Subscribe
Mds 9513
Subscribe
Mds 9706
Subscribe
Mds 9710
Subscribe
Mds 9718
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24441 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-15T17:37:52.004Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3170
Updated: 2024-08-04T07:24:00.616Z
Status : Modified
Published: 2020-02-26T17:15:13.140
Modified: 2024-11-21T05:30:28.420
Link: CVE-2020-3170
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD