CVE-2013-1178 - CVE House
Back to Database
Status published High CVE-2013-1178

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation...

Vulnerability Description

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1178

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nx-os, nexus 7000, nexus 7000 10-slot, nexus 7000 18-slot, nexus 7000 9-slot, mds 9000, nexus 5000, nexus 5010, nexus 5020, nexus 5548p, nexus 5548up, nexus 5596up, nexus 4001i, nexus 3000, nexus 3016q, nexus 3048, nexus 3064t, nexus 3064x, nexus 3548, nexus 1000v, unified computing system infrastructure and unified computing system software, unified computing system 6120xp fabric interconnect, unified computing system 6140xp fabric interconnect, unified computing system 6248up fabric interconnect, unified computing system 6296up fabric interconnect, cg-os, connected grid router 1000
Vulnerable Versions:
4.0, 4.0\(0\)n1\(1a\), 4.0\(0\)n1\(2\), 4.0\(0\)n1\(2a\), 4.0\(1a\)n1\(1\), 4.0\(1a\)n1\(1a\), 4.0\(1a\)n2\(1\), 4.0\(1a\)n2\(1a\), 4.0\(4\)sv1\(1\), 4.0\(4\)sv1\(2\), 4.0\(4\)sv1\(3\), 4.0\(4\)sv1\(3a\), 4.0\(4\)sv1\(3b\), 4.0\(4\)sv1\(3c\), 4.0\(4\)sv1\(3d\), 4.1\(3\)n1\(1\), 4.1\(3\)n1\(1a\), 4.1\(3\)n2\(1\), 4.1\(3\)n2\(1a\), 4.1.\(2\), 4.1.\(3\), 4.1.\(4\), 4.1.\(5\), 4.2, 4.2\(1\), 4.2\(1\)n1\(1\), 4.2\(1\)n2\(1\), 4.2\(1\)n2\(1a\), 4.2\(1\)sv1\(4\), 4.2\(1\)sv1\(4a\), 4.2\(1\)sv1\(5.1\), 4.2\(2\), 4.2\(3\), 4.2\(4\), 4.2\(6\), 4.2\(8\), 4.2.\(2a\), 5.0, 5.0\(2\), 5.0\(2\)n1\(1\), 5.0\(2\)n2\(1\), 5.0\(2\)n2\(1a\), 5.0\(2a\), 5.0\(3\), 5.0\(3\)n1\(1\), 5.0\(3\)n1\(1a\), 5.0\(3\)n1\(1b\), 5.0\(3\)n1\(1c\), 5.0\(3\)n2\(1\), 5.0\(3\)n2\(2\), 5.0\(3\)n2\(2a\), 5.0\(3\)n2\(2b\), 5.0\(5\), 5.1, 5.1\(1\), 5.1\(1a\), 5.1\(2\), 5.1\(3\), 5.1\(3\)n1\(1\), 5.1\(3\)n1\(1a\), 5.1\(4\), 5.1\(5\), 5.1\(6\), 5.2, 5.2\(1\), 5.2\(3\), 5.2\(3a\), 6.0\(1\), 6.0\(2\), 6.1, 0, 1.0, 1.0\(2k\), 1.1, 1.1\(1m\), 1.2, 1.2\(1\), 1.2\(1a\), 1.2\(1d\), 1.3\(1c\), 1.3\(1m\), 1.3\(1n\), 1.3\(1o\), 1.3\(1p\), 1.3\(1q\), 1.3\(1t\), 1.3\(1w\), 1.3\(1y\), 1.4\(1j\), 1.4\(1m\), 1.4\(3i\), 1.4\(3l\), 1.4\(3m\), 1.4\(3q\), 1.4\(3s\), 1.4\(3u\), 1.4\(3y\), 1.4\(4f\), 1.4\(4g\), 1.4\(4i\), 1.4\(4j\), 1.4\(4k\), 2.0\(1q\), 2.0\(1s\), 2.0\(1t\), 2.0\(1w\), cg1, cg2, cg3

Timeline

Official Publish: April 25th, 2013
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.