Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105836
Category:CISCO
Title:Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability (cisco-sa-20160727-avs)
Summary:A vulnerability in Cisco Discovery Protocol packet processing; for the Cisco Nexus 1000v Application Virtual Switch (AVS) could allow an unauthenticated, remote; attacker to cause the ESXi hypervisor to crash and display a purple diagnostic screen, resulting; in a denial of service (DoS) condition.
Description:Summary:
A vulnerability in Cisco Discovery Protocol packet processing
for the Cisco Nexus 1000v Application Virtual Switch (AVS) could allow an unauthenticated, remote
attacker to cause the ESXi hypervisor to crash and display a purple diagnostic screen, resulting
in a denial of service (DoS) condition.

Vulnerability Insight:
The vulnerability is due to insufficient input validation of
Cisco Discovery Protocol packets, which could result in a crash of the ESXi hypervisor due to an
out-of-bound memory access.

Vulnerability Impact:
An attacker could exploit this vulnerability by sending a
crafted Cisco Discovery Protocol packet to a targeted device. An exploit could allow the attacker
to cause a DoS condition.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
6.1

CVSS Vector:
AV:A/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-1465
BugTraq ID: 92154
http://www.securityfocus.com/bid/92154
Cisco Security Advisory: 20160727 Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-avs
http://www.securitytracker.com/id/1036469
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.