QID 317016

Date Published: 2021-08-26

QID 317016: Cisco NX-OS Software MPLS OAM Denial of Service Vulnerability (cisco-sa-nxos-mpls-oam-dos-sGO9x5GM)

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products
Following Cisco products if they are running a vulnerable release of Cisco NX-OS Software and
have the MPLS OAM feature enabled:
Nexus 3000 Series Switches
Nexus 7000 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.

A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times,
causing the affected device to reload and resulting in a DoS condition.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-nxos-mpls-oam-dos-sGO9x5GM for more information.

    CVEs related to QID 317016

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-nxos-mpls-oam-dos-sGO9x5GM URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-mpls-oam-dos-sGO9x5GM