Cisco NX-OS Software Netstack Denial of Service Vulnerability
Published Mar 7, 2019
8.6
HIGHCVSS 3.1
EPSS 14.28%
Description
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could exploit this vulnerability by sending crafted TCP streams to an affected device in a sustained way. A successful exploit could cause the network stack of an affected device to run out of available buffers, impairing operations of control plane and management plane protocols, resulting in a DoS condition. Note: This vulnerability can be triggered only by traffic that is destined to an affected device and cannot be exploited using traffic that transits an affected device. Nexus 1000V Switch for Microsoft Hyper-V is affected in versions prior to 5.2(1)SM3(2.1). Nexus 1000V Switch for VMware vSphere is affected in versions prior to 5.2(1)SV3(4.1a). Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(6) and 9.2(2). Nexus 3500 Platform Switches are affected in versions prior to 6.0(2)A8(11), 7.0(3)I7(6), and 9.2(2). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5) and 9.2(2). Nexus 5500, 5600, and 6000 Series Switches are affected in versions prior to 7.1(5)N1(1b) and 7.3(5)N1(1). Nexus 7000 and 7700 Series Switches are affected in versions prior to 6.2(22. Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5) and 9.2(2). UCS 6200 and 6300 Series Fabric Interconnect are affected in versions prior to 3.2(3j) and 4.0(2a). UCS 6400 Series Fabric Interconnect are affected in versions prior to 4.0(2a).
Affected products
-
- Version unspecifiedStatusaffectedConstraints<5.2(1)SM3(2.1)
- Version
-
- Version unspecifiedStatusaffectedConstraints<5.2(1)SV3(4.1a)
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.0(3)I7(6)
- Version unspecifiedStatusaffectedConstraints<9.2(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<6.0(2)A8(11)
- Version unspecifiedStatusaffectedConstraints<7.0(3)I7(6)
- Version unspecifiedStatusaffectedConstraints<9.2(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.0(3)F3(5)
- Version unspecifiedStatusaffectedConstraints<9.2(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.1(5)N1(1b)
- Version unspecifiedStatusaffectedConstraints<7.3(5)N1(1)
- Version
-
- Version unspecifiedStatusaffectedConstraints<6.2(22)
- Version unspecifiedStatusaffectedConstraints<7.3(3)D1(1)
- Version unspecifiedStatusaffectedConstraints<8.2(3)
- Version unspecifiedStatusaffectedConstraints<8.3(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.0(3)I7(6)
- Version unspecifiedStatusaffectedConstraints<9.2(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.0(3)F3(5)
- Version unspecifiedStatusaffectedConstraints<9.2(2)
- Version
-
- Version unspecifiedStatusaffectedConstraints<3.2(3j)
- Version unspecifiedStatusaffectedConstraints<4.0(2a)
- Version
-
- Version unspecifiedStatusaffectedConstraints<4.0(2a)
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cisco | Nexus 1000V Switch for Microsoft Hyper-V | n/a |
| |||||||||||||||
| Cisco | Nexus 1000V Switch for VMware vSphere | n/a |
| |||||||||||||||
| Cisco | Nexus 3000 Series Switches | n/a |
| |||||||||||||||
| Cisco | Nexus 3500 Platform Switches | n/a |
| |||||||||||||||
| Cisco | Nexus 3600 Platform Switches | n/a |
| |||||||||||||||
| Cisco | Nexus 5500, 5600, and 6000 Series Switches | n/a |
| |||||||||||||||
| Cisco | Nexus 7000 and 7700 Series Switches | n/a |
| |||||||||||||||
| Cisco | Nexus 9000 Series Switches in Standalone NX-OS Mode | n/a |
| |||||||||||||||
| Cisco | Nexus 9500 R-Series Line Cards and Fabric Modules | n/a |
| |||||||||||||||
| Cisco | UCS 6200 and 6300 Series Fabric Interconnect | n/a |
| |||||||||||||||
| Cisco | UCS 6400 Series Fabric Interconnect | n/a |
|
Configuration 1
Running on/with
- n/a
- n/a
- n/a
Configuration 2
Running on/with
- n/a
Configuration 3
Running on/with
- n/a
Configuration 4
Running on/with
- n/a
- n/a
- n/a
Configuration 5
Running on/with
- n/a
- n/a
Configuration 6
Running on/with
- n/a
- n/a
Configuration 7
Running on/with
- n/a
Configuration 8
Running on/with
- n/a
- n/a
Configuration 9
Running on/with
- n/a
Configuration 10
Running on/with
- n/a
Configuration 11
Running on/with
- n/a
Configuration 12
Running on/with
- n/a
Configuration 13
Configuration 14
Configuration 15
Configuration 16
Running on/with
- n/a
Configuration 17
Running on/with
- n/a
- n/a
- n/a
Configuration 18
Running on/with
- n/a
- n/a
Configuration 19
Running on/with
- n/a
- n/a
Configuration 20
Running on/with
- n/a
Configuration 21
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Nov 19, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 14.28% (0.14283) | 96.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 14.17% (0.14166) | 96.10th | v5 (v2026.06.15) |
| Nov 21, 2025 | 5.86% (0.05861) | 90.16th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.60% (0.02603) | 84.31th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.85% (0.06848) | 90.46th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.05% (0.09046) | 87.59th | v4 (v2025.03.14) |
| Mar 19, 2025 | 6.85% (0.06848) | 90.20th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.67% (0.03672) | 87.11th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.16% (0.00157) | 52.55th | v3 (v2023.03.01) |
| Jun 26, 2024 | 0.16% (0.00157) | 52.35th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.16% (0.00157) | 50.35th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.05% (0.01055) | 50.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.50% (0.04499) | 74.08th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.24% (0.04237) | 74.61th | v1 |
| Jan 6, 2022 | 4.24% (0.04237) | 74.40th | v1 |
| Sep 1, 2021 | 0.98% (0.00976) | 61.78th | v1 |
| Apr 14, 2021 | 0.98% (0.00976) | 0.00th | v1 |
References (2)
- http://www.securityfocus.com/bid/107342 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-netstack vendor-advisoryx_refsource_CISCOPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107342 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-netstack | vendor-advisoryx_refsource_CISCOPatchVendor Advisory |
Change history (0)
No recorded changes yet.