A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted Cisco UDLD protocol packets to a directly connected, affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the Cisco UDLD process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. The attacker needs full control of a directly connected device. That device must be connected over a port channel that has UDLD enabled. To trigger arbitrary code execution, both the UDLD-enabled port channel and specific system conditions must exist. In the absence of either the UDLD-enabled port channel or the system conditions, attempts to exploit this vulnerability will result in a DoS condition. It is possible, but highly unlikely, that an attacker could control the necessary conditions for exploitation. The CVSS score reflects this possibility. However, given the complexity of exploitation, Cisco has assigned a Medium Security Impact Rating (SIR) to this vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Firepower 4110
Subscribe
Firepower 4112
Subscribe
Firepower 4115
Subscribe
Firepower 4120
Subscribe
Firepower 4125
Subscribe
Firepower 4140
Subscribe
Firepower 4145
Subscribe
Firepower 4150
Subscribe
Firepower 9300
Subscribe
Firepower Extensible Operating System
Subscribe
Mds 9148s
Subscribe
Mds 9250i
Subscribe
Mds 9706
Subscribe
Mds 9710
Subscribe
Nexus 3048
Subscribe
Nexus 31108pv-v
Subscribe
Nexus 31108tc-v
Subscribe
Nexus 31128pq
Subscribe
Nexus 3132c-z
Subscribe
Nexus 3132q-v
Subscribe
Nexus 3132q-x
Subscribe
Nexus 3132q-xl
Subscribe
Nexus 3164q
Subscribe
Nexus 3172pq
Subscribe
Nexus 3172pq-xl
Subscribe
Nexus 3232c
Subscribe
Nexus 3264c-e
Subscribe
Nexus 3264q
Subscribe
Nexus 3408-s
Subscribe
Nexus 34180yc
Subscribe
Nexus 3432d-s
Subscribe
Nexus 3464c
Subscribe
Nexus 3524-x
Subscribe
Nexus 3524-xl
Subscribe
Nexus 3548-x
Subscribe
Nexus 3548-xl
Subscribe
Nexus 36180yc-r
Subscribe
Nexus 3636c-r
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5624q
Subscribe
Nexus 5648q
Subscribe
Nexus 5672up
Subscribe
Nexus 5672up-16g
Subscribe
Nexus 5696q
Subscribe
Nexus 6001
Subscribe
Nexus 6004
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nexus 9000v
Subscribe
Nexus 92160yc-x
Subscribe
Nexus 9221c
Subscribe
Nexus 92300yc
Subscribe
Nexus 92304qc
Subscribe
Nexus 92348gc-x
Subscribe
Nexus 9236c
Subscribe
Nexus 9272q
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93108tc-ex-24
Subscribe
Nexus 93108tc-fx
Subscribe
Nexus 93108tc-fx-24
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 9316d-gx
Subscribe
Nexus 93180lc-ex
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 93180yc-ex-24
Subscribe
Nexus 93180yc-fx
Subscribe
Nexus 93180yc-fx-24
Subscribe
Nexus 93180yc-fx3
Subscribe
Nexus 93180yc-fx3s
Subscribe
Nexus 93216tc-fx2
Subscribe
Nexus 93240yc-fx2
Subscribe
Nexus 9332pq
Subscribe
Nexus 93360yc-fx2
Subscribe
Nexus 9336c-fx2
Subscribe
Nexus 9336c-fx2-e
Subscribe
Nexus 9336pq
Subscribe
Nexus 9348gc-fxp
Subscribe
Nexus 93600cd-gx
Subscribe
Nexus 9364c
Subscribe
Nexus 9364c-gx
Subscribe
Nexus 9372px
Subscribe
Nexus 9372px-e
Subscribe
Nexus 9372tx
Subscribe
Nexus 9372tx-e
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9508
Subscribe
Nx-os
Subscribe
Ucs 6248up
Subscribe
Ucs 6296up
Subscribe
Ucs 6324
Subscribe
Ucs 6332
Subscribe
Ucs 6332-16up
Subscribe
Ucs 64108
Subscribe
Ucs 6454
Subscribe
Unified Computing System
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6835 | A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted Cisco UDLD protocol packets to a directly connected, affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the Cisco UDLD process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. The attacker needs full control of a directly connected device. That device must be connected over a port channel that has UDLD enabled. To trigger arbitrary code execution, both the UDLD-enabled port channel and specific system conditions must exist. In the absence of either the UDLD-enabled port channel or the system conditions, attempts to exploit this vulnerability will result in a DoS condition. It is possible, but highly unlikely, that an attacker could control the necessary conditions for exploitation. The CVSS score reflects this possibility. However, given the complexity of exploitation, Cisco has assigned a Medium Security Impact Rating (SIR) to this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:37:56.190Z
Reserved: 2020-11-13T00:00:00
Link: CVE-2021-1368
Updated: 2024-08-03T16:11:16.857Z
Status : Modified
Published: 2021-02-24T20:15:13.473
Modified: 2024-11-21T05:44:11.723
Link: CVE-2021-1368
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD