QID 317296

Date Published: 2023-03-22

QID 317296: Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode Link Layer Discovery Protocol (LLDP) Memory Leak Denial of Service (DoS) Vulnerability (cisco-sa-aci-lldp-dos-ySCNZOpX)

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device.

Affected Products
Cisco Nexus 9000 Series Fabric Switches in ACI mode if they were running a vulnerable release of Cisco NX-OS Software and using the default configuration.

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.

A successful exploit could allow the attacker to cause a memory leak, which could result in a denial of service (DoS) condition when the device unexpectedly reloads.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-aci-lldp-dos-ySCNZOpX for more information.

    CVEs related to QID 317296

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-aci-lldp-dos-ySCNZOpX URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-lldp-dos-ySCNZOpX