PT-2019-2648 · Cisco · Cisco Application Policy Infrastructure Controller+1
Publicado
2019-07-03
·
Atualizado
2020-10-16
·
CVE-2019-1890
CVSS v3.1
7.4
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 9000 Series ACI Mode Switch (affected versions not specified)
Description
The issue is related to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN, allowing an unauthenticated, adjacent attacker to bypass security validations. By sending a malicious LLDP packet, an attacker could connect an unauthorized server to the infrastructure VLAN, which has high privileges. This could enable the attacker to make unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or join other host endpoints.
Recommendations
For the Cisco Nexus 9000 Series ACI Mode Switch, consider restricting access to the infrastructure VLAN to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using the LLDP protocol in the adjacent subnet to the Cisco Nexus 9000 Series Switch in ACI mode until the issue is resolved.
Restrict access to the Cisco Application Policy Infrastructure Controller (APIC) services to prevent unauthorized connections.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Application Policy Infrastructure Controller
Cisco Nexus 9000 Series Aci Mode Switch