Cisco Bug: CSCup85616 - SNMP Leaks configured VLAN IDs to unauthenticated users
Feb 13, 2018
- Cisco Nexus 7000 Series Switches
Known Affected Releases
Symptom: A vulnerability in the SNMP module of NX-OS could allow an unauthenticated, remote attacker to disclose potentially sensitive information. The vulnerability is due to a failure to respond to invalid requests in the same manner when specifying a VLAN ID. An attacker could exploit this vulnerability by making a large number of requests to the listening SNMP port of an affected device. A successful exploit could allow the attacker to enumerate VLANs that are configured on the affected device. Cisco would like to thank Ehab Hussein of IOActive for discovering and reporting this vulnerability. Conditions: Devices with SNMP and VLAN ID's configured. This vulnerability affects Nexus 5000 series and Nexus 6000 series devices running an affected version of NX-OS software.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases