PT-2021-2161 · Cisco · Cisco Nexus 9000 Series Fabric Switches
Adrien Peter
·
Published
2021-02-24
·
Updated
2022-09-20
·
CVE-2021-1231
CVSS v3.1
4.7
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode (affected versions not specified)
Description
A vulnerability in the Link Layer Discovery Protocol (LLDP) could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this by sending a crafted LLDP packet on an SFP interface to an affected device, potentially disrupting network traffic.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nexus 9000 Series Fabric Switches