CVE-2019-1965 is a denial-of-service vulnerability in the Virtual Shell (VSH) session management of Cisco NX-OS Software. It allows an authenticated, remote attacker to cause VSH processes to accumulate, eventually depleting system memory and leading to unexpected behavior or crashes. The vulnerability has a CVSS score of 7.7 (HIGH), indicating a network-based attack with low complexity, requiring valid user credentials, and resulting in a high impact on availability. There is no evidence of active exploitation, nor is public exploit code available, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2, < 6.2\(29\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.3, < 8.4CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\)f, < 9.2CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
< 7.1\(5\)n1\(1b\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.3, < 7.3\(5\)n1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.