Vulnerabilities > Cisco > Nexus 1000V

DATE CVE VULNERABILITY TITLE RISK
2013-07-10 CVE-2013-3400 Improper Input Validation vulnerability in Cisco Nexus 1000V and Nx-Os
The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.
local
low complexity
cisco CWE-20
6.8
2013-05-29 CVE-2013-1213 Resource Management Errors vulnerability in Cisco Nexus 1000V and Nx-Os
Cisco NX-OS on the Nexus 1000V does not assign the proper priority to heartbeat messages from a Virtual Ethernet Module (VEM) to a Virtual Supervisor Module (VSM), which allows remote attackers to cause a denial of service (false VEM unavailability report) via a flood of UDP packets, aka Bug ID CSCud14840.
network
low complexity
cisco CWE-399
5.0
2013-05-29 CVE-2013-1212 Cryptographic Issues vulnerability in Cisco Nexus 1000V and Nx-Os
The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a crafted certificate, aka Bug ID CSCud14837.
network
cisco CWE-310
5.8
2013-05-29 CVE-2013-1211 Improper Authentication vulnerability in Cisco Nx-Os
Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM access via (1) spoofed STUN packets or (2) a crafted VMware ESXi instance, aka Bug ID CSCud14832.
network
low complexity
cisco CWE-287
5.0
2013-05-29 CVE-2013-1210 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco Nx-Os
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and purple screen of death) by sending crafted STUN packets to a VEM, aka Bug ID CSCud14825.
network
high complexity
cisco CWE-119
5.4
2013-05-29 CVE-2013-1209 Improper Authentication vulnerability in Cisco Nx-Os
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM packets, which allows remote attackers to disable packet-level encryption and integrity protection via crafted packets, aka Bug ID CSCud14710.
network
low complexity
cisco CWE-287
5.0
2013-05-29 CVE-2013-1208 Cryptographic Issues vulnerability in Cisco Nx-Os
The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers to intercept or modify network traffic by leveraging certain Layer 2 or Layer 3 access, aka Bug ID CSCud14691.
network
cisco CWE-310
5.8
2013-04-25 CVE-2013-1178 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.
low complexity
cisco CWE-119
8.3
2012-02-16 CVE-2012-0352 Resource Management Errors vulnerability in Cisco products
Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x before 4.2.8, 5.0.x before 5.0.5, and 5.1.x before 5.1.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (netstack process crash and device reload) via a malformed IP packet, aka Bug IDs CSCti23447, CSCti49507, and CSCtj01991.
network
low complexity
cisco CWE-399
7.8