A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deplete system memory. When there is no system memory available, this can cause unexpected system behaviors and crashes. The vulnerability is due to the VSH process not being properly deleted when a remote management connection to the device is disconnected. An attacker could exploit this vulnerability by repeatedly performing a remote management connection to the device and terminating the connection in an unexpected manner. A successful exploit could allow the attacker to cause the VSH processes to fail to delete, which can lead to a system-wide denial of service (DoS) condition. The attacker must have valid user credentials to log in to the device using the remote management connection.
                
            Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
Exploitation none
Automatable no
Technical Impact partial
Affected Vendors & Products
| Vendors | Products | 
|---|---|
| Cisco | 
 | 
Configuration 1 [-]
| AND | 
 
 | 
Configuration 2 [-]
| AND | 
 
 | 
Configuration 3 [-]
| AND | 
 
 | 
Configuration 4 [-]
| AND | 
 
 | 
Configuration 5 [-]
| AND | 
 
 | 
Configuration 6 [-]
| AND | 
 
 | 
Configuration 7 [-]
| AND | 
 
 | 
No data.
References
        History
                    Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2019-08-28T18:55:13.586838Z
Updated: 2024-11-21T19:15:13.546Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1965
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T18:35:51.782Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-08-28T19:15:11.053
Modified: 2024-11-21T04:37:47.067
Link: CVE-2019-1965
 Redhat
                        Redhat
                    No data.