CVE-2019-1597 describes multiple denial-of-service vulnerabilities in the LDAP feature of various Cisco FXOS and NX-OS products, including Firepower, MDS, Nexus, and UCS devices. An unauthenticated, remote attacker can exploit improper LDAP packet parsing by sending a specially crafted BER-encoded LDAP packet from a configured LDAP server's IP address. This high-severity vulnerability (CVSS 7.5) could cause affected devices to reload, leading to a denial-of-service condition. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 2.2.2.54, < 2.3.1.75CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
< 8.2\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
< 7.0\(3\)i7\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
< 7.0\(3\)i7\(2\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
> 7.3\(2\)d1\(1\), < 8.2\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.