Cisco Bug: CSCuw36684 - Cisco Nexus 3000 SNMP Non-Existent OID Denial of Service Vulnerability
Apr 26, 2017
- Cisco Nexus 3000 Series Switches
Known Affected Releases
Symptom: A vulnerability in Simple Network Management Protocol (SNMP) interface of the Nexus 3000 (N3K) Series Switch could allow an authenticated, remote attacker to cause a partial denial of service (DoS) condition to the SNMP service running on the device. The vulnerability is due to improper handling of a SNMP request with a non-existent Object Identifier (OID). An attacker could exploit this vulnerability by sending a crafted SNMP request to the affected device. An exploit could allow the attacker to cause a partial DoS condition of the SNMP interface where SNMP requests with legitimately formatted OIDs will timeout. The DoS condition does clear and SNMP requests will start to be processed normally as expected. Conditions: Device running with default configuration running an affected version of software with SNMP globally.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases