QID 317335

Date Published: 2023-07-13

QID 317335: Cisco Application Centric Infrastructure (ACI) Multi-Site CloudSec Encryption Information Disclosure Vulnerability (cisco-sa-aci-cloudsec-enc-Vs5Wn2sX)

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.

Note: Making this QID as practice as we cannot add Multi-Site topology configuration check in signature.

Affected Products
This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode that are running releases 14.0 and later if they are part of a Multi-Site topology and have the CloudSec encryption feature enabled.

QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.

A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-aci-cloudsec-enc-Vs5Wn2sX for more information.

    CVEs related to QID 317335

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-aci-cloudsec-enc-Vs5Wn2sX URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX