CVE-2018-0301 describes a critical buffer overflow vulnerability in the NX-API feature of Cisco NX-OS Software, impacting various Nexus and MDS 9000 series switches. This flaw, caused by incorrect input validation, allows an unauthenticated, remote attacker to execute arbitrary code as root by sending a crafted HTTP/HTTPS packet to the management interface if NX-API is enabled. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). While NX-API is disabled by default, there is no evidence of active exploitation, nor are public exploit modules like Metasploit or Nuclei available. However, the vulnerability has received some community and media attention, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, < 7.3\(3\)n1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.2, < 7.3\(2\)d1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.