CVE-2013-1178: Cisco Cg-OS

High severity, CVSS 8.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.

Affected products

  • Cisco Cg-OS: up to and including cg4; version cg1 only; version cg2 only; version cg3 only
  • Cisco Connected Grid Router 1000
  • Cisco Mds 9000
  • Cisco Nexus 1000v
  • Cisco Nexus 3000
  • Cisco Nexus 3016q
  • Cisco Nexus 3048
  • Cisco Nexus 3064t
  • Cisco Nexus 3064x
  • Cisco Nexus 3548
  • Cisco Nexus 4001i
  • Cisco Nexus 5000
  • Cisco Nexus 5010
  • Cisco Nexus 5020
  • Cisco Nexus 5548p
  • Cisco Nexus 5548up
  • Cisco Nexus 5596up
  • Cisco Nexus 7000
  • Cisco Nexus 7000 10-Slot
  • Cisco Nexus 7000 18-Slot
  • Cisco Nexus 7000 9-Slot
  • Cisco NX-OS: version 4.0 only; version 4.0(0)n1(1a) only; version 4.0(0)n1(2) only; version 4.0(0)n1(2a) only; version 4.0(1a)n1(1) only; version 4.0(1a)n1(1a) only; …
  • Cisco Unified Computing System 6120xp Fabric Interconnect
  • Cisco Unified Computing System 6140xp Fabric Interconnect
  • Cisco Unified Computing System 6248up Fabric Interconnect
  • and 2 more

Published 2013-04-25. Last modified 2026-06-16.