A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-lldap-dos-WerV9CFj | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-02-24 12:15
Updated : 2022-09-20 10:06
NVD link : CVE-2021-1231
Mitre link : CVE-2021-1231
JSON object : View
CWE
CWE-346
Origin Validation Error
Products Affected
cisco
- nexus_9372tx-e
- nexus_9236c
- nexus_9336pq_aci_spine
- nexus_9372px
- nexus_93108tc-ex
- nexus_9336c-fx2
- nexus_93240yc-fx2
- nexus_9364c-gx
- nexus_93108tc-fx
- nexus_93180yc-fx3s
- nexus_92348gc-x
- nexus_93180yc-fx-24
- nexus_93120tx
- nexus_93216tc-fx2
- nexus_9372px-e
- nexus_93180lc-ex
- nexus_93108tc-ex-24
- nexus_93108tc-fx-24
- nexus_93360yc-fx2
- nexus_93180yc-ex
- nexus_93180yc-fx3
- nexus_9336c-fx2-e
- nexus_92160yc-x
- nexus_93600cd-gx
- nexus_9364c
- nexus_92300yc
- nexus_9272q
- nexus_93128tx
- nexus_9372tx
- nexus_93180yc-fx
- nexus_9332c
- nexus_93180yc-ex-24
- nx-os
- nexus_9316d-gx
- nexus_9396px
- nexus_9332pq
- nexus_9000v
- nexus_92304qc
- nexus_9348gc-fxp
- nexus_9508
- nexus_9396tx