Database/Firmware, BMC & network fabric
Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switch
CVSS 8.6CVE-2017-3883Firmware, BMC & network fabriccurated
Impact
AAA implementation flaw enabling remote DoS via brute-force login attempts against the switch management plane
Who can reach it
Network, unauthenticated
What to do
NX-OS/FXOS upgrade; also a reason to keep switch management auth off any tenant-reachable path
References
Related entries
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughCVE-2018-0378 · Cisco NX-OS PTP feature (Nexus 5500/5600/6000)High
- Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is aCVE-2021-1587 · Cisco NX-OS (VXLAN OAM / NGOAM)High
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): Improper input validation in the *manageability*CVE-2021-33141 · Intel Ethernet Adapter manageability firmware (NC-SI / sideband path)High
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontCVE-2022-2601 · GRUB2 (font engine, grub_font_construct_glyph)High
- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseCVE-2022-36392 · Intel AMT / Standard Manageability firmwareHigh
- GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of boundsCVE-2022-3775 · GRUB2 (font engine, blit_comb)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.