Guest

Preview Tool

Cisco Bug: CSCvt70484 - CVE-2017-8779 exploit on open rpcbind port could lead to remote DoS

Last Modified

Apr 18, 2020

Products (1)

  • Cisco Data Center Network Manager

Known Affected Releases

11.4(0.137)

Description (partial)

Symptom:
This issue is applicable only when customers do not have their firewall. Since release 11.2.1 we have advised customers to deploy and most do and exclude only followings ports. This is a standard practice in a data center.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/11_3_1/installation/san/b_dcnm_installation_guide_for_san_11_3_1/m_running_dcnm_behind_firewall.html


This product includes a version of rpcbind that is affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs:

CVE-2017-8779

This bug was opened to address the potential impact on this product.

Conditions:
Device with default configuration.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.