cisco nx-os CVE-2019-1969 is a vulnerability in Cisco Nx Os
Published on August 30, 2019

Cisco NX-OS Software SNMP Access Control List Configuration Name Bypass Vulnerability
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic. The vulnerability is due to an incorrect length check when the configured ACL name is the maximum length, which is 32 ASCII characters. An attacker could exploit this vulnerability by performing SNMP polling of an affected device. A successful exploit could allow the attacker to perform SNMP polling that should have been denied. The attacker has no control of the configuration of the SNMP ACL name.

Vendor Advisory NVD

Weakness Type

Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.


Products Associated with CVE-2019-1969

Want to know whenever a new CVE is published for Cisco Nx Os? stack.watch will email you.

 

Affected Versions

Cisco NX-OS Software:

Exploit Probability

EPSS
0.70%
Percentile
71.78%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.