Rewterz Threat Advisory – CVE-2019-11085 – Linux Kernel Intel i915 Graphics Driver Privilege Escalation Vulnerability
May 17, 2019Rewterz Threat Advisory – CVE-2019-11634 – Citrix Multiple Products Security Bypass Vulnerability
May 21, 2019Rewterz Threat Advisory – CVE-2019-11085 – Linux Kernel Intel i915 Graphics Driver Privilege Escalation Vulnerability
May 17, 2019Rewterz Threat Advisory – CVE-2019-11634 – Citrix Multiple Products Security Bypass Vulnerability
May 21, 2019Severity
Medium
Analysis Summary
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is due to improper error handling when processing inbound SNMP packets. An attacker could exploit this vulnerability by sending multiple crafted SNMP packets to an affected device. A successful exploit could allow the attacker to cause the SNMP application to leak system memory because of an improperly handled error condition during packet processing. Over time, this memory leak could cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition.
Impact
Denial of Service
Affected Vendors
Cisco
Affected Products
- Cisco Firepower 4100 Series
- Cisco Firepower 9300 Security Appliances
- Cisco MDS 9000 Series Multilayer Switches
- Cisco Nexus 1000V Switch for Microsoft Hyper-V
- Cisco Nexus 1000V Switch for VMware vSphere
- Cisco Nexus 3000 Series Switches
- Cisco Nexus 3500 Platform Switches
- Cisco Nexus 5500 Platform Switches
- Cisco Nexus 5600 Platform Switches
- Cisco Nexus 6000 Series Switches
- Cisco Nexus 7000 Series Switches
- Cisco Nexus 7700 Series Switches
- Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode
- Cisco Nexus 9000 Series Switches in standalone NX-OS mode
- Cisco Nexus 9500 R-Series Switching Platform
Remediation
Vendor has released updates/patches for the following products.