PT-2021-2178 · Cisco · Cisco Application Policy Infrastructure Controller+1

Adrien Peter

·

Published

2021-02-24

·

Updated

2022-09-20

·

CVE-2021-1228

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode (affected versions not specified)
Description A vulnerability in the fabric infrastructure VLAN connection establishment could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. This issue is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this by sending a crafted LLDP packet on the adjacent subnet to an affected device, potentially allowing unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or other host endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01085
CVE-2021-1228

Affected Products

Cisco Application Policy Infrastructure Controller
Cisco Nexus 9000 Series Fabric Switches