Vulnerability Name:

CVE-2016-1465 (CCN-115495)

Assigned:2016-07-27
Published:2016-07-27
Updated:2017-09-01
Summary:Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.0 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.1 Medium (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
6.1 Medium (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2016-1465

Source: CISCO
Type: Vendor Advisory
20160727 Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability

Source: BID
Type: UNKNOWN
92154

Source: CCN
Type: BID-92154
Cisco Nexus 1000v Application Virtual Switch CVE-2016-1465 Denial of Service Vulnerability

Source: SECTRACK
Type: UNKNOWN
1036469

Source: XF
Type: UNKNOWN
cisco-nexus-cve20161465-dos(115495)

Source: CCN
Type: Cisco Security Advisory cisco-sa-20160727-avs
Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:nx-os:4.0(4)sv1(1):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(2):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(3):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(3a):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(3b):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(3c):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.0(4)sv1(3d):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(4):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(4a):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(4b):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(5.1):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(5.1a):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(5.2):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv1(5.2b):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv2(1.1):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv2(1.1a):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv2(2.1):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:4.2(1)sv2(2.1a):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:5.2(1)sv3(1.1):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:5.2(1)sv3(1.3):*:*:*:*:*:*:*
  • OR cpe:/o:cisco:nx-os:5.2(1)sv3(1.4):*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:nexus_1000v:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco nx-os 4.0(4)sv1(1)
    cisco nx-os 4.0(4)sv1(2)
    cisco nx-os 4.0(4)sv1(3)
    cisco nx-os 4.0(4)sv1(3a)
    cisco nx-os 4.0(4)sv1(3b)
    cisco nx-os 4.0(4)sv1(3c)
    cisco nx-os 4.0(4)sv1(3d)
    cisco nx-os 4.2(1)sv1(4)
    cisco nx-os 4.2(1)sv1(4a)
    cisco nx-os 4.2(1)sv1(4b)
    cisco nx-os 4.2(1)sv1(5.1)
    cisco nx-os 4.2(1)sv1(5.1a)
    cisco nx-os 4.2(1)sv1(5.2)
    cisco nx-os 4.2(1)sv1(5.2b)
    cisco nx-os 4.2(1)sv2(1.1)
    cisco nx-os 4.2(1)sv2(1.1a)
    cisco nx-os 4.2(1)sv2(2.1)
    cisco nx-os 4.2(1)sv2(2.1a)
    cisco nx-os 5.2(1)sv3(1.1)
    cisco nx-os 5.2(1)sv3(1.3)
    cisco nx-os 5.2(1)sv3(1.4)
    cisco nexus 1000v -