GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco Fabric

CVE-2018-0314Firmware, BMC & network fabriccurated

Impact

Unauthenticated remote code execution as root through Cisco Fabric Services, the inter-switch distribution protocol. CFS is on by default on many platforms and speaks between switches, so a single compromised switch or a host that can spoof CFS reaches every other switch that trusts the same distribution domain. Part of a 2018 cluster (CVE-2018-0304/0308/0310/0312/0314) that shares this exposure.

Who can reach it

Unauthenticated, remote — the attacker must be able to send CFS messages, which in an unsegmented fabric means any host on a VLAN where CFS-over-IP is enabled.

What to do

NX-OS upgrade plus reload. Immediately: disable CFS distribution and CFS-over-IP where you do not use it (no cfs distribute, no cfs ipv4 distribute) — live config, no reload, and it closes the whole 2018 family at once.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.