CVE-2018-0310 describes a critical vulnerability in the Cisco Fabric Services component of Cisco FXOS and NX-OS Software, affecting numerous Cisco networking devices including various Nexus series switches and Firepower appliances. This flaw allows an unauthenticated, remote attacker to send a crafted packet, leading to a buffer overread condition. The severity is rated 9.8 Critical, indicating a high potential for sensitive information disclosure or a denial of service (DoS) condition due to its network-based attack vector and low attack complexity. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, and it is not listed in CISA's KEV catalog, community discussion indicates significant interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0\(0\)hsk\(0.357\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:7.0\(0\)hsk\(0.357\):*:*:*:*:*:*:* | ||
8.1\(0.2\)s0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1\(0.2\)s0:*:*:*:*:*:*:* | ||
8.8\(0.1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.8\(0.1\):*:*:*:*:*:*:* | ||
8.0\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.0\(1\):*:*:*:*:*:*:* | ||
8.8\(3.5\)s0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.8\(3.5\)s0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.