Cisco fixes vulnerabilities in FXOS, UCS Manager and NX
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3175 | A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote att A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource usage control. An attacker could exploit this vulnerability by sending traffic to the management interface (mgmt0) of an affected device at very high rates. An exploit could allow the attacker to cause unexpected behaviors such as high CPU usage, process crashes, or even full system reboots of an affected device. NVD description · AI analysis pending | 8.6 group max | 2% |
| — | ||
| CVE-2020-3167 +1 in the same advisory: …3166 | A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on t A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2020-3172 +1 in the same advisory: …3169 | A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to exe A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to a Layer 2-adjacent affected device. A successful exploit could allow the attacker to cause a buffer overflow that could allow the attacker to execute arbitrary code as root or cause a DoS condition on the affected device. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Note: This vulnerability is different from the following Cisco FXOS and NX-OS Software Cisco Discovery Protocol vulnerabilities that Cisco announced on Feb. 5, 2020: Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability and Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2020-3173 | A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary command A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by including crafted arguments to specific commands on the local management CLI. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — |
Full article454 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 28, 2020

Cisco released security patches for 11 vulnerabilities in its products, including the Cisco UCS Manager, FXOS, and the NX-OS software.
The most severe vulnerabilities, rated as high severity, affect FXOS and NX-OS that could be exploited by an unauthenticated, adjacent attacker to execute arbitrary code as root.
The exploitation of the flaw could trigger a denial of service (DoS) condition.
“All six vulnerabilities have a Security Impact Rating (SIR) of High. Successful exploitation of the vulnerabilities could allow an attacker to gain elevated privileges, execute arbitrary commands, or cause a denial of service (DoS) condition on an affected device.” reads the advisory published by Cisco.
“Two vulnerabilities affect only Cisco NX-OS Software; one vulnerability affects only Cisco UCS Software; two vulnerabilities affect both Cisco FXOS Software and Cisco UCS Software; and one vulnerability affects Cisco FX-OS Software, Cisco NX-OS Software, and UCS Software.”
The first issue tracked as CVE-2020-3172 is caused by the lack of insufficient validation of Cisco Discovery Protocol packet headers. The flaw could be exploited by an attacker to send a crafted packet to a Layer 2-adjacent vulnerable device and trigger a buffer overflow to run arbitrary code or cause a DoS condition.
The vulnerability impacts several devices for which the Discovery Protocol is enabled by default, including Nexus, Firepower, UCS and MDS.
The IT giant fixed a high severity flaw in the UCS Manager software (CVE-2020-3173) that could be exploited by an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The flaw impacts UCS 6200, 6300, and 6400 Series Fabric Interconnects.
Cisco also addressed another a high risk DoS vulnerability in NX-OS software for MDS 9000 Series Multilayer Switches, the flaw tracked as CVE-2020-3175 can be exploited by a remote, unauthenticated attacker.
Other high severity issues fixed by the tech giant are:
- A DoS flaw in Secure Login Enhancements capability of the Nexus 1000V switch for VMware vSphere, tracked as CVE-2020-3168, that could be exploited by an unauthenticated, remote attacker to cause a vulnerable Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible.
- A CLI command injection flaw CVE-2020-3167 in FXOS software that could be exploited by an authenticated, local attacker to execute arbitrary commands. The issue affects Firepower and UCS products.
- A CLI command injection flaw CVE-2020- 3171 in UCS Manager software that could be exploited by an authenticated, local attacker to execute arbitrary commands. The issue affects Firepower and UCS products.
The company also addressed three medium severity vulnerabilities, tracked as CVE-2020-3165, CVE-2020-3174, CVE-2020-3170, in the NX-OS software and two other medium risk bugs in the FXOS software tracked as CVE-2020-3166 and CVE-2020-3169.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, security)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/98620/hacking/cisco-flaws-fxos-ucs-nx-os.html