Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities
Cisco warns NGOAM flaws in NX-OS on Nexus 3000 and 9000 switches allow unauthenticated remote root code execution.
Cisco disclosed multiple vulnerabilities in the NGOAM feature of NX-OS Software on Nexus 3000 and 9000 Series switches. An unauthenticated remote attacker could send crafted packets to an IP interface and execute arbitrary code with root privileges or cause a denial of service and device reload. The bugs are due to improper validation of IP traffic when NGOAM is enabled. The advisory does not report that exploitation has been observed.
- Unauthenticated remote attackers could gain root on affected switches.
- Flaws are improper input validation in NGOAM when enabled.
- Crafted IP packets can crash processes and reload the device.
- The advisory does not report active exploitation.
Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit these vulnerabilities by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.