A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the unexpected restart of the IS-IS process, which could cause the affected device to reload. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2 adjacent to the affected device.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the unexpected restart of the IS-IS process, which could cause the affected device to reload. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2 adjacent to the affected device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Nexus 3048
Subscribe
Nexus 31108pc-v
Subscribe
Nexus 31108tc-v
Subscribe
Nexus 31128pq
Subscribe
Nexus 3132c-z
Subscribe
Nexus 3132q-v
Subscribe
Nexus 3132q-xl
Subscribe
Nexus 3164q
Subscribe
Nexus 3172pq
Subscribe
Nexus 3172pq-xl
Subscribe
Nexus 3172tq
Subscribe
Nexus 3172tq-32t
Subscribe
Nexus 3172tq-xl
Subscribe
Nexus 3232
Subscribe
Nexus 3264c-e
Subscribe
Nexus 3264q
Subscribe
Nexus 3408-s
Subscribe
Nexus 34180yc
Subscribe
Nexus 34200yc-sm
Subscribe
Nexus 3432d-s
Subscribe
Nexus 3464c
Subscribe
Nexus 3524
Subscribe
Nexus 3524-x
Subscribe
Nexus 3524-xl
Subscribe
Nexus 3548
Subscribe
Nexus 3548-x
Subscribe
Nexus 3548-xl
Subscribe
Nexus 36180yc-r
Subscribe
Nexus 9232e
Subscribe
Nexus 92348gc-x
Subscribe
Nexus 9408
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24348 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the unexpected restart of the IS-IS process, which could cause the affected device to reload. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2 adjacent to the affected device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-02T09:05:36.905Z
Reserved: 2022-10-27T18:47:50.362Z
Link: CVE-2023-20169
No data.
Status : Modified
Published: 2023-08-23T19:15:07.893
Modified: 2024-11-21T07:40:44.107
Link: CVE-2023-20169
No data.
OpenCVE Enrichment
No data.
EUVD