QID 317335
Date Published: 2023-07-13
QID 317335: Cisco Application Centric Infrastructure (ACI) Multi-Site CloudSec Encryption Information Disclosure Vulnerability (cisco-sa-aci-cloudsec-enc-Vs5Wn2sX)
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.
Note: Making this QID as practice as we cannot add Multi-Site topology configuration check in signature.
Affected Products
This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode that are running releases 14.0 and later if they are part of a Multi-Site topology and have the CloudSec encryption feature enabled.
QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.
A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.
Customers are advised to refer to cisco-sa-aci-cloudsec-enc-Vs5Wn2sX for more information.
- cisco-sa-aci-cloudsec-enc-Vs5Wn2sX -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX
CVEs related to QID 317335
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-aci-cloudsec-enc-Vs5Wn2sX |
|