CVE-2019-1901 Details
Description
A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode if they are running a Cisco Nexus 9000 Series ACI Mode Switch Software release prior to 13.2(7f) or any 14.x release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo | CVE | Vendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190731-nxos-bo | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco nx-os | < 13.2\(7f\) >= 14.0\(1h\), <= 14.1\(2g\) |
CPE
Remediation
| |
| cisco nexus 93108tc-ex | All versions |
CPE
Remediation
| |
| cisco nexus 93108tc-fx | All versions |
CPE
Remediation
| |
| cisco nexus 93120tx | All versions |
CPE
Remediation
| |
| cisco nexus 93128tx | All versions |
CPE
Remediation
| |
| cisco nexus 93180lc-ex | All versions |
CPE
Remediation
| |
| cisco nexus 93180yc-ex | All versions |
CPE
Remediation
| |
| cisco nexus 93180yc-fx | All versions |
CPE
Remediation
| |
| cisco nexus 9332pq | All versions |
CPE
Remediation
| |
| cisco nexus 9336c-fx2 | All versions |
CPE
Remediation
| |
| cisco nexus 9336pq | All versions |
CPE
Remediation
| |
| cisco nexus 9348gc-fxp | All versions |
CPE
Remediation
| |
| cisco nexus 9364c | All versions |
CPE
Remediation
| |
| cisco nexus 9372px | All versions |
CPE
Remediation
| |
| cisco nexus 9372px-e | All versions |
CPE
Remediation
| |
| cisco nexus 9372tx | All versions |
CPE
Remediation
| |
| cisco nexus 9372tx-e | All versions |
CPE
Remediation
| |
| cisco nexus 9396px | All versions |
CPE
Remediation
| |
| cisco nexus 9396tx | All versions |
CPE
Remediation
| |
| cisco nexus 9504 | All versions |
CPE
Remediation
| |
| cisco nexus 9508 | All versions |
CPE
Remediation
| |
| cisco nexus 9516 | All versions |
CPE
Remediation
| |
| cisco nexus 93240yc-fx2 | All versions |
CPE
Remediation
| |
| cisco nexus 9332c | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 3, 2023 | Modified Analysis | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Aug 12, 2019 | Initial Analysis | [email protected] |