Guest

Preview Tool

Cisco Bug: CSCuw36684 - Cisco Nexus 3000 SNMP Non-Existent OID Denial of Service Vulnerability

Last Modified

Apr 26, 2017

Products (1)

  • Cisco Nexus 3000 Series Switches

Known Affected Releases

6.0(2)U6(0.46)

Description (partial)

Symptom:
A vulnerability in Simple Network Management Protocol (SNMP) interface of the Nexus 3000 (N3K) Series Switch 
could allow an authenticated, remote attacker to cause a partial denial of service (DoS) condition to the SNMP
service running on the device.

The vulnerability is due to improper handling of a SNMP request with a non-existent Object Identifier (OID). An attacker 
could exploit this vulnerability by sending a crafted SNMP request to the affected device. An exploit could allow the 
attacker to cause a partial DoS condition of the SNMP interface where SNMP requests with legitimately formatted OIDs
will timeout. The DoS condition does clear and SNMP requests will start to be processed normally as expected.

Conditions:
Device running with default configuration running an affected version of software with SNMP globally.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.