Description
A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-10534 | A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism. |
References
History
Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Nexus 9000
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93108tc-fx
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 93180lc-ex
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 93180yc-fx
Subscribe
Nexus 9332pq
Subscribe
Nexus 9336c-fx2
Subscribe
Nexus 9336pq
Subscribe
Nexus 9348gc-fxp
Subscribe
Nexus 9364c
Subscribe
Nexus 9372px
Subscribe
Nexus 9372px-e
Subscribe
Nexus 9372tx
Subscribe
Nexus 9372tx-e
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-21T19:15:02.726Z
Reserved: 2018-12-06T00:00:00.000Z
Link: CVE-2019-1977
Updated: 2024-08-04T18:35:51.847Z
Status : Modified
Published: 2019-08-30T09:15:20.553
Modified: 2024-11-21T04:37:48.753
Link: CVE-2019-1977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD