A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources when the affected device is logging a drop action for received MODE_PRIVATE (Mode 7) NTP packets. An attacker could exploit this vulnerability by flooding the device with a steady stream of Mode 7 NTP packets. A successful exploit could allow the attacker to cause high CPU and memory usage on the affected device, which could cause internal system processes to restart or cause the affected device to unexpectedly reload. Note: The NTP feature is enabled by default.
                
            Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Changed
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
This CVE is not in the KEV list.
Exploitation none
Automatable yes
Technical Impact partial
Affected Vendors & Products
| Vendors | Products | 
|---|---|
| Cisco | 
 | 
Configuration 1 [-]
| AND | 
 
 | 
Configuration 2 [-]
| AND | 
 
 | 
Configuration 3 [-]
| AND | 
 
 | 
Configuration 4 [-]
| AND | 
 
 | 
Configuration 5 [-]
| AND | 
 
 | 
Configuration 6 [-]
| AND | 
 
 | 
No data.
References
        History
                    Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2019-08-29T21:45:15.166469Z
Updated: 2024-11-19T18:58:07.518Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1967
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T18:35:51.286Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-08-30T09:15:20.287
Modified: 2024-11-21T04:37:47.367
Link: CVE-2019-1967
 Redhat
                        Redhat
                    No data.