QID 316926
Date Published: 2021-04-15
QID 316926: Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability(cisco-sa-20161102-n9kapic)
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
Affected Version:
APIC version 1.2(2x) prior to 1.2(2j)
APIC version 1.2(3x) prior to 1.2(3l)
APIC version 1.3(1x) prior to 1.3(1j)
APIC version 1.3(2x) prior to 1.3(2j)
APIC version 2.0(1x) prior to 2.0(1r)
The vulnerability is due to improper handling of a type of Layer 2 control plane traffic. An attacker could exploit this vulnerability by sending crafted traffic to a host behind a leaf switch. An exploit could allow the attacker to cause a DoS condition on the affected device.
Solution
Customers are advised to refer to cisco-sa-20161102-n9kapic for more information.
Vendor References
- cisco-sa-20161102-n9kapic -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-n9kapic
CVEs related to QID 316926
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20161102-n9kapic |
|