PT-2021-2178 · Cisco · Cisco Application Policy Infrastructure Controller+1
Adrien Peter
·
Published
2021-02-24
·
Updated
2022-09-20
·
CVE-2021-1228
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode (affected versions not specified)
Description
A vulnerability in the fabric infrastructure VLAN connection establishment could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. This issue is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this by sending a crafted LLDP packet on the adjacent subnet to an affected device, potentially allowing unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or other host endpoints.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Application Policy Infrastructure Controller
Cisco Nexus 9000 Series Fabric Switches