Cisco Bug: CSCvt70484 - CVE-2017-8779 exploit on open rpcbind port could lead to remote DoS
Apr 18, 2020
- Cisco Data Center Network Manager
Known Affected Releases
Symptom: This issue is applicable only when customers do not have their firewall. Since release 11.2.1 we have advised customers to deploy and most do and exclude only followings ports. This is a standard practice in a data center. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/11_3_1/installation/san/b_dcnm_installation_guide_for_san_11_3_1/m_running_dcnm_behind_firewall.html This product includes a version of rpcbind that is affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs: CVE-2017-8779 This bug was opened to address the potential impact on this product. Conditions: Device with default configuration.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases