Junglewise Threat Intelligence

CVE-2017-3804: Cisco Nexus Switches DoS in IS-IS packet processing

CVE-2017-3804 · Severity: medium · CVSS 6.1 · Published 2017-01-26

Vendors: Cisco.

Executive brief

A vulnerability in Cisco Nexus switches could allow a nearby attacker to crash the device, leading to a complete network service outage. The issue affects switches using the FabricPath feature when they process specifically malformed network routing packets. A successful exploit results in a device reload, disrupting all connected traffic and operations until the hardware restarts.

Technical details

A denial of service vulnerability exists in the Intermediate System-to-Intermediate System (IS-IS) protocol implementation within Cisco NX-OS. The root cause is improper processing of crafted IS-IS link-state packets within a FabricPath domain, leading to an '__inst_001__isis_fabricpath' HAP reset. An unauthenticated attacker located on the same adjacent network segment can exploit this by sending a malformed packet over an established adjacency. This results in a device reload (crash). Patches have been released for various branches of NX-OS, including versions 6.2, 7.0, 7.1, 7.2, 7.3, 8.0, and 8.3.

Affected products

  • Cisco Nexus 5000 Series Switches 7.1(3)N1(2.1), 7.1(3)N1(3.12), 7.3(2)N1(0.296)
  • Cisco Nexus 6000 Series Switches 7.1(3)N1(2.1), 7.1(3)N1(3.12), 7.3(2)N1(0.296)
  • Cisco Nexus 7000 Series Switches 8.0(1)S2

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication

References