Cisco NX-OS Software Unexpected IP in IP Packet Processing Vulnerability (cisco-sa-nxos-ipip-dos-kCT9X4)

medium Nessus Plugin ID 137184

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, the Cisco NX-OS Software is affected by a denial of service vulnerability in the network stack due to the affected device unexpectedly decapsulating and processing IP in IP packets that are destined to a locally configured IP address. An unauthenticated, remote attacker can exploit this issue by sending a crafted IP in IP packet to an affected device, to bypass certain security boundaries or cause a denial of service condition on an affected device.

Solution

Upgrade to the relevant fixed version or apply the workaround referenced in Cisco bug IDs CSCun53663, CSCvt66624, CSCvt67738, CSCvt67739, CSCvt67740, CSCvu03158 and CSCvu10050 or alternatively apply the workaround mentioned in the advisory.

See Also

http://www.nessus.org/u?0f50ed05

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCun53663

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt66624

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt67738

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt67739

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt67740

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu03158

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu10050

Plugin Details

Severity: Medium

ID: 137184

File Name: cisco-sa-nxos-ipip-dos-kCT9X4.nasl

Version: 1.9

Type: combined

Family: CISCO

Published: 6/5/2020

Updated: 6/4/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2020-10136

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:nx-os

Required KB Items: Host/Cisco/NX-OS/Version, Host/Cisco/NX-OS/Model, Host/Cisco/NX-OS/Device

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/1/2020

Vulnerability Publication Date: 6/1/2020

Reference Information

CVE: CVE-2020-10136