CVE-2019-1901
Last modified
CVE-2019-1901 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode if they are running a Cisco Nexus 9000 Series ACI Mode Switch Software release prior to 13.2(7f) or any 14.x release.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | < 13.2\(7f\) |
| Cisco | Nx-Os | >= 14.0\(1h\), <= 14.1\(2g\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1901?
How severe is CVE-2019-1901?
How do I fix CVE-2019-1901?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19003For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is no…6.1
- CVE-2019-19004A biWidth*biBitCnt integer overflow in input-bmp.c in autotr…3.3
- CVE-2019-19005A bitmap double free in main.c in autotrace 0.31.1 allows at…7.8
- CVE-2019-19006Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below,…9.8
- CVE-2019-19007Intelbras IWR 3000N 1.8.7 devices allow disclosure of the ad…7.2
- CVE-2019-19008Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-19010Eval injection in the Math plugin of Limnoria (before 2019.1…9.8
- CVE-2019-19011MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIn…7.5
- CVE-2019-19012An integer overflow in the search_in_range function in regex…9.8
- CVE-2019-19013A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to…8.8
- CVE-2019-19014An issue was discovered in TitanHQ WebTitan before 5.18. It …7.8
- CVE-2019-19015An issue was discovered in TitanHQ WebTitan before 5.18. The…9.8
Are you affected by CVE-2019-1901?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
