QID 317137

Date Published: 2022-05-09

QID 317137: Cisco Nexus Operating System (NX-OS) Software Denial of Service (DoS) Vulnerability (cisco-sa-cfsoip-dos-tpykyDr)

A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco NX-OS Software and have the CFSoIP feature enabled:

Nexus 3000 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
UCS 6400 Series Fabric Interconnects

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.

A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-cfsoip-dos-tpykyDr for more information.

    CVEs related to QID 317137

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-cfsoip-dos-tpykyDr URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cfsoip-dos-tpykyDr