cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
915
Views
0
Helpful
2
Replies

Cisco SX10/SX20 show vulnerability nginx <= 1.21.1 Information

Lucas Phelps
Level 5
Level 5

We just had a security audit and their scanner detected a vulnerability in all our SX10 and SX20s called nginx <= 1.21.1 Information Disclosure Vulnerability with CVE-2013-0337. I am on the newest firmware and opened a ticket with tac but they said the scanner is wrong basically. Anyone have some ideas?

2 Replies 2

Chad Vickers
Level 1
Level 1

I actually have 5 separate nginx vulnerabilities on our SX10s and SX80s. I haven't entered a TAC case yet.

-nginx Data Disclosure Vulnerability (CVE-2017-7529)

-nginx 1.x < 1.14.1 / 1.15.x < 1.15.6 Multiple Vulnerabilities (CVE-2018-16843, 16844, 16845)

-nginx < 1.17.7 Information Disclosure (CVE-2019-20372)

-nginx 0.6.x < 1.20.1 1-Byte Memory Overwrite RCE (CVE-2021-23017)

-nginx < 1.10.1 / 1.11.x < 1.11.1 Denial-of-Service Vulnerability (CVE-2016-4450)

 

 

 

Seref Tozun
Level 1
Level 1

I have  nginx vulnerabilities on our SX20s. I haven't opened a TAC case yet. Before ı want to ask you. Did you learn anything about this topic?

-nginx 0.6.x < 1.20.1 1-Byte Memory Overwrite RCE (CVE-2021-23017)