CVE-2018-0378

A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of protection against PTP frame flood attacks. An attacker could exploit this vulnerability by sending large streams of malicious IPv4 or IPv6 PTP traffic to the affected device. A successful exploit could allow the attacker to cause a DoS condition, impacting the traffic passing through the device.

Published : 2018-10-17 21:49 Updated : 2019-10-09 23:31

7.8
CVSS Score More info
Score 7.8 / 10
7.8
Vendor Product Version URI
Cisco Nx-os 7.3%282%29n1%280.8%29 cpe:/o:cisco:nx-os:7.3%282%29n1%280.8%29
  1. Cisco (1) Search CVE
    1. Nx-os (1) Search CVE
      1. 7.3%282%29n1%280.8%29

CWE

ID Name Description Links
CWE-20 Improper Input Validation The product does not validate or incorrectly validates input that can affect the control flow or data flow of a program. CVE

History of changes

Date Event
2019-02-15 21:57
2018-10-19 10:29
2018-10-17 21:49

New CVE