CVE-2013-1178
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.
- CVSS 2.0
- 8.3 HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- cisco/nx-os · cisco/nexus 7000 · cisco/nexus 7000 10-slot · cisco/nexus 7000 18-slot · cisco/nexus 7000 9-slot · cisco/mds 9000 · cisco/nexus 5000 · cisco/nexus 5010 · cisco/nexus 5020 · cisco/nexus 5548p · cisco/nexus 5548up · cisco/nexus 5596up · cisco/nexus 4001i · cisco/nexus 3000 · cisco/nexus 3016q · cisco/nexus 3048 · cisco/nexus 3064t · cisco/nexus 3064x · cisco/nexus 3548 · cisco/nexus 1000v · +7 more
- Source
- psirt@cisco.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.