imPC@ndo IT

Tracker / CVE-2014-3341

CVE-2014-3341

Medium 5.0

The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.

Affected products and versions

cisco nexus_5000
cisco nexus_5010
cisco nexus_5010p_switch
cisco nexus_5020
cisco nexus_5020p_switch
cisco nexus_5548p
cisco nexus_5548up
cisco nexus_5596t
cisco nexus_5596up
cisco nexus_56128p
cisco nexus_5672up
cisco nexus_6001
cisco nexus_6004
cisco nexus_6004x
cisco nx-os
cisco nx-os · … → 7.0\(3\)n1\(1\)

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References