HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-1587

CVSS 8.6v3.1pub. 2021-08-25upd. 2024-11-21

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific packets with a Transparent Interconnection of Lots of Links (TRILL) OAM EtherType. An attacker could exploit this vulnerability by sending crafted packets, including the TRILL OAM EtherType of 0x8902, to a device that is part of a VXLAN Ethernet VPN (EVPN) fabric. A successful exploit could allow the attacker to cause an affected device to experience high CPU usage and consume excessive system resources, which may result in overall control plane instability and cause the affected device to reload. Note: The NGOAM feature is disabled by default.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco Nexus 3000

    HW
    Cisco
    all versions
  • Cisco Nexus 3048

    HW
    Cisco
    all versions
  • Cisco Nexus 31108pc V

    HW
    Cisco
    all versions
  • Cisco Nexus 31108tc V

    HW
    Cisco
    all versions
  • Cisco Nexus 31128pq

    HW
    Cisco
    all versions
  • Cisco Nexus 3132c Z

    HW
    Cisco
    all versions
  • Cisco Nexus 3132q V

    HW
    Cisco
    all versions
  • Cisco Nexus 3132q X\/3132q Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3164q

    HW
    Cisco
    all versions
  • Cisco Nexus 3172pq\/pq Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3172tq Xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3232c

    HW
    Cisco
    all versions
  • Cisco Nexus 3264c E

    HW
    Cisco
    all versions
  • Cisco Nexus 3264q

    HW
    Cisco
    all versions
  • Cisco Nexus 3408 S

    HW
    Cisco
    all versions
  • Cisco Nexus 34180yc

    HW
    Cisco
    all versions
  • Cisco Nexus 3432d S

    HW
    Cisco
    all versions
  • Cisco Nexus 3464c

    HW
    Cisco
    all versions
  • Cisco Nexus 3524 X\/xl

    HW
    Cisco
    all versions
  • Cisco Nexus 3548 X\/xl

    HW
    Cisco
    all versions
  • Cisco Nexus 36180yc R

    HW
    Cisco
    all versions
  • Cisco Nexus 3636c R

    HW
    Cisco
    all versions
  • Cisco Nexus 9000v

    HW
    Cisco
    all versions
  • Cisco Nexus 92160yc X

    HW
    Cisco
    all versions
  • Cisco Nexus 92300yc

    HW
    Cisco
    all versions
  • Cisco Nexus 92304qc

    HW
    Cisco
    all versions
  • Cisco Nexus 92348gc X

    HW
    Cisco
    all versions
  • Cisco Nexus 9236c

    HW
    Cisco
    all versions
  • Cisco Nexus 9272q

    HW
    Cisco
    all versions
  • Cisco Nexus 93108tc Ex

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSVPN
CWE
References

Related vulnerabilities

CVE-2021-1361CRITICAL9.8PL ✓same product

Cisco NX-OS: nieautoryzowany dostęp do plików przez port TCP 9075

CVE-2019-1804CRITICAL9.8PL ✓same product

Domyślna para kluczy SSH w Cisco Nexus 9000 ACI umożliwia dostęp root

CVE-2018-0310CRITICAL9.8PL ✓same product

Cisco FXOS/NX-OS: buffer overread w Cisco Fabric Services umożliwia DoS lub wyciek danych

CVE-2018-0301CRITICAL9.8PL ✓same product

Cisco NX-OS NX-API — buffer overflow umożliwiający RCE jako root

CVE-2018-0312CRITICAL9.8PL ✓same product

RCE i DoS w Cisco Fabric Services — buffer overflow w FXOS/NX-OS