QID 317020

Date Published: 2021-08-26

QID 317020: Cisco Nexus 9000 Series Fabric Switches ACI Mode Multi-Pod and Multi-Site TCP Denial of Service Vulnerability (cisco-sa-n9kaci-tcp-dos-YXukt6gM)

A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in a denial of service (DoS) condition.

Affected Products
Cisco Nexus 9000 Series Fabric Switches in ACI mode if they have Multi-Pod or Multi-Site configured and have an IP address configured on the spine layer Inter-Pod Network (IPN) or Inter-Site Network (ISN) interface.

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.

A successful exploit could allow the attacker to cause the device to restart unexpectedly, resulting in a DoS condition.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-n9kaci-tcp-dos-YXukt6gM for more information.

    CVEs related to QID 317020

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-n9kaci-tcp-dos-YXukt6gM URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9kaci-tcp-dos-YXukt6gM