CVE-2019-1616 is a high-severity vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software, affecting various Cisco MDS, Nexus, and UCS series switches. This flaw, due to insufficient packet validation, allows an unauthenticated, remote attacker to trigger a buffer overflow by sending a crafted packet, leading to process crashes and a denial of service (DoS) condition. With a CVSS score of 7.5, it has a low attack complexity and requires no user interaction or privileges. While there are no known public exploits or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.2, < 8.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\), < 7.0\(3\)i7\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\)i5, < 7.0\(3\)i7\(4\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\)f3, < 7.0\(3\)f3\(3c\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.2, < 8.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.