Description
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24441 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API on an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition in the NX-API service; however, the Cisco NX-OS device itself would still be available and passing network traffic. Note: The NX-API feature is disabled by default. |
References
History
Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Mds 9132t
Subscribe
Mds 9148s
Subscribe
Mds 9148t
Subscribe
Mds 9216
Subscribe
Mds 9216a
Subscribe
Mds 9216i
Subscribe
Mds 9222i
Subscribe
Mds 9506
Subscribe
Mds 9509
Subscribe
Mds 9513
Subscribe
Mds 9706
Subscribe
Mds 9710
Subscribe
Mds 9718
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nx-os
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-15T17:37:52.004Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2020-3170
Updated: 2024-08-04T07:24:00.616Z
Status : Modified
Published: 2020-02-26T17:15:13.140
Modified: 2024-11-21T05:30:28.420
Link: CVE-2020-3170
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD