A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Nexus 9000v
Subscribe
Nexus 92160yc-x
Subscribe
Nexus 92300yc
Subscribe
Nexus 92304qc
Subscribe
Nexus 92348gc-x
Subscribe
Nexus 9236c
Subscribe
Nexus 9272q
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93108tc-ex-24
Subscribe
Nexus 93108tc-fx
Subscribe
Nexus 93108tc-fx-24
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 9316d-gx
Subscribe
Nexus 93180lc-ex
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 93180yc-ex-24
Subscribe
Nexus 93180yc-fx
Subscribe
Nexus 93180yc-fx-24
Subscribe
Nexus 93180yc-fx3
Subscribe
Nexus 93180yc-fx3s
Subscribe
Nexus 93216tc-fx2
Subscribe
Nexus 93240yc-fx2
Subscribe
Nexus 9332c
Subscribe
Nexus 9332pq
Subscribe
Nexus 93360yc-fx2
Subscribe
Nexus 9336c-fx2
Subscribe
Nexus 9336c-fx2-e
Subscribe
Nexus 9336pq Aci Spine
Subscribe
Nexus 9348gc-fxp
Subscribe
Nexus 93600cd-gx
Subscribe
Nexus 9364c
Subscribe
Nexus 9364c-gx
Subscribe
Nexus 9372px
Subscribe
Nexus 9372px-e
Subscribe
Nexus 9372tx
Subscribe
Nexus 9372tx-e
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9508
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6698 | A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:38:56.652Z
Reserved: 2020-11-13T00:00:00
Link: CVE-2021-1231
Updated: 2024-08-03T16:02:56.339Z
Status : Modified
Published: 2021-02-24T20:15:13.193
Modified: 2024-11-21T05:43:53.150
Link: CVE-2021-1231
No data.
OpenCVE Enrichment
No data.
EUVD