CVE-2017-3883 Details
Description
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03846en_us | CVE | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-aaavty | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/101493 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039614 | CVE | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03846en_us | [email protected] | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-aaavty | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/101493 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039614 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco firepower extensible operating system | <= 2.3 |
CPE
Remediation
| |
| cisco firepower 4100 | All versions |
CPE
Remediation
| |
| cisco fxos | 2.3 |
CPE
Remediation
| |
| cisco firepower 9300 | All versions |
CPE
Remediation
| |
| cisco nx-os | 5.2 6.2 6.3 7.3 8.1 8.2 <= 4.1 <= 6.0 7.0 7.0(3)i3(1) <= 5.2 7.1(0.1) 6.1 <= 2.2 2.5 3.0 3.1 3.2 |
CPE
Remediation
| |
| cisco mds 9000 | All versions |
CPE
Remediation
| |
| cisco nexus 1000v | All versions |
CPE
Remediation
| |
| cisco nexus 1100v | All versions |
CPE
Remediation
| |
| cisco nexus 3000 | All versions |
CPE
Remediation
| |
| cisco nexus 3016 | All versions |
CPE
Remediation
| |
| cisco nexus 3016q | All versions |
CPE
Remediation
| |
| cisco nexus 3048 | All versions |
CPE
Remediation
| |
| cisco nexus 3064 | All versions |
CPE
Remediation
| |
| cisco nexus 3064t | All versions |
CPE
Remediation
| |
| cisco nexus 3064x | All versions |
CPE
Remediation
| |
| cisco nexus 3500 | All versions |
CPE
Remediation
| |
| cisco nexus 3524 | All versions |
CPE
Remediation
| |
| cisco nexus 3548 | All versions |
CPE
Remediation
| |
| cisco nexus 2000 | All versions |
CPE
Remediation
| |
| cisco nexus 5000 | All versions |
CPE
Remediation
| |
| cisco nexus 5010 | All versions |
CPE
Remediation
| |
| cisco nexus 5010p switch | All versions |
CPE
Remediation
| |
| cisco nexus 5500 | All versions |
CPE
Remediation
| |
| cisco nexus 5548p | All versions |
CPE
Remediation
| |
| cisco nexus 5548up | All versions |
CPE
Remediation
| |
| cisco nexus 5596t | All versions |
CPE
Remediation
| |
| cisco nexus 5596up | All versions |
CPE
Remediation
| |
| cisco nexus 5600 | All versions |
CPE
Remediation
| |
| cisco nexus 56128p | All versions |
CPE
Remediation
| |
| cisco nexus 5624q | All versions |
CPE
Remediation
| |
| cisco nexus 5648q | All versions |
CPE
Remediation
| |
| cisco nexus 5672up | All versions |
CPE
Remediation
| |
| cisco nexus 5696q | All versions |
CPE
Remediation
| |
| cisco nexus 6000 | All versions |
CPE
Remediation
| |
| cisco nexus 6001 | All versions |
CPE
Remediation
| |
| cisco nexus 6004 | All versions |
CPE
Remediation
| |
| cisco nexus 6004x | All versions |
CPE
Remediation
| |
| cisco nexus 7000 | All versions |
CPE
Remediation
| |
| cisco nexus 7000 10-slot | All versions |
CPE
Remediation
| |
| cisco nexus 7000 18-slot | All versions |
CPE
Remediation
| |
| cisco nexus 7000 9-slot | All versions |
CPE
Remediation
| |
| cisco nexus 7700 | All versions |
CPE
Remediation
| |
| cisco nexus 9000 | All versions |
CPE
Remediation
| |
| cisco 9500 r | All versions |
CPE
Remediation
| |
| cisco ucs 6100 | All versions |
CPE
Remediation
| |
| cisco ucs 6200 | All versions |
CPE
Remediation
| |
| cisco ucs 6300 | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 20, 2023 | CPE Deprecation Remap | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 29, 2018 | CVE Modified | [email protected] |
| Nov 7, 2017 | Initial Analysis | [email protected] |
| Oct 23, 2017 | CVE Modified | [email protected] |
| Oct 20, 2017 | CVE Modified | [email protected] |