CVE-2013-1180 describes a critical buffer overflow vulnerability in the SNMP implementation of Cisco NX-OS, affecting Nexus 7000 and MDS 9000 series devices running specific firmware versions. A remote authenticated attacker can exploit this flaw by sending a specially crafted SNMP request, leading to arbitrary code execution. With a CVSS score of 9.0, this vulnerability is highly severe, requiring only network access and authenticated credentials for exploitation, with complete compromise of confidentiality, integrity, and availability. While no public exploit code or Metasploit modules are available, and there's no evidence of active exploitation, the high impact warrants attention. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0:*:*:*:*:*:*:* | ||
4.0\(0\)n1\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(0\)n1\(1a\):*:*:*:*:*:*:* | ||
4.0\(0\)n1\(2\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(0\)n1\(2\):*:*:*:*:*:*:* | ||
4.0\(0\)n1\(2a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(0\)n1\(2a\):*:*:*:*:*:*:* | ||
4.0\(1a\)n1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(1a\)n1\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.