A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific packets with a Transparent Interconnection of Lots of Links (TRILL) OAM EtherType. An attacker could exploit this vulnerability by sending crafted packets, including the TRILL OAM EtherType of 0x8902, to a device that is part of a VXLAN Ethernet VPN (EVPN) fabric. A successful exploit could allow the attacker to cause an affected device to experience high CPU usage and consume excessive system resources, which may result in overall control plane instability and cause the affected device to reload. Note: The NGOAM feature is disabled by default.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HCisco Nexus 3000
HWCiscoall versionsCisco Nexus 3048
HWCiscoall versionsCisco Nexus 31108pc V
HWCiscoall versionsCisco Nexus 31108tc V
HWCiscoall versionsCisco Nexus 31128pq
HWCiscoall versionsCisco Nexus 3132c Z
HWCiscoall versionsCisco Nexus 3132q V
HWCiscoall versionsCisco Nexus 3132q X\/3132q Xl
HWCiscoall versionsCisco Nexus 3164q
HWCiscoall versionsCisco Nexus 3172pq\/pq Xl
HWCiscoall versionsCisco Nexus 3172tq Xl
HWCiscoall versionsCisco Nexus 3232c
HWCiscoall versionsCisco Nexus 3264c E
HWCiscoall versionsCisco Nexus 3264q
HWCiscoall versionsCisco Nexus 3408 S
HWCiscoall versionsCisco Nexus 34180yc
HWCiscoall versionsCisco Nexus 3432d S
HWCiscoall versionsCisco Nexus 3464c
HWCiscoall versionsCisco Nexus 3524 X\/xl
HWCiscoall versionsCisco Nexus 3548 X\/xl
HWCiscoall versionsCisco Nexus 36180yc R
HWCiscoall versionsCisco Nexus 3636c R
HWCiscoall versionsCisco Nexus 9000v
HWCiscoall versionsCisco Nexus 92160yc X
HWCiscoall versionsCisco Nexus 92300yc
HWCiscoall versionsCisco Nexus 92304qc
HWCiscoall versionsCisco Nexus 92348gc X
HWCiscoall versionsCisco Nexus 9236c
HWCiscoall versionsCisco Nexus 9272q
HWCiscoall versionsCisco Nexus 93108tc Ex
HWCiscoall versions
Related vulnerabilities
Cisco NX-OS: nieautoryzowany dostęp do plików przez port TCP 9075
Domyślna para kluczy SSH w Cisco Nexus 9000 ACI umożliwia dostęp root
Cisco FXOS/NX-OS: buffer overread w Cisco Fabric Services umożliwia DoS lub wyciek danych
Cisco NX-OS NX-API — buffer overflow umożliwiający RCE jako root
RCE i DoS w Cisco Fabric Services — buffer overflow w FXOS/NX-OS