CVE-2021-1368
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted Cisco UDLD protocol packets to a directly connected, affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the Cisco UDLD process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The UDLD feature is disabled by default, and the conditions to exploit this vulnerability are strict. The attacker needs full control of a directly connected device. That device must be connected over a port channel that has UDLD enabled. To trigger arbitrary code execution, both the UDLD-enabled port channel and specific system conditions must exist. In the absence of either the UDLD-enabled port channel or the system conditions, attempts to exploit this vulnerability will result in a DoS condition. It is possible, but highly unlikely, that an attacker could control the necessary conditions for exploitation. The CVSS score reflects this possibility. However, given the complexity of exploitation, Cisco has assigned a Medium Security Impact Rating (SIR) to this vulnerability.
Affected (10)
Configuration A
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0(3)i5(2) |
| Running on/with | Platform Versions |
|---|---|
Cisco Nexus 3048 | All versions |
Cisco Nexus 31108pv V | All versions |
Cisco Nexus 31108tc V | All versions |
Cisco Nexus 31128pq | All versions |
Cisco Nexus 3132c Z | All versions |
Cisco Nexus 3132q V | All versions |
Cisco Nexus 3132q X | All versions |
Cisco Nexus 3132q Xl | All versions |
Cisco Nexus 3164q | All versions |
Cisco Nexus 3172pq | All versions |
Cisco Nexus 3172pq Xl | All versions |
Cisco Nexus 3232c | All versions |
Cisco Nexus 3264c E | All versions |
Cisco Nexus 3264q | All versions |
Cisco Nexus 3408 S | All versions |
Cisco Nexus 34180yc | All versions |
Cisco Nexus 3432d S | All versions |
Cisco Nexus 3464c | All versions |
Cisco Nexus 3524 X | All versions |
Cisco Nexus 3524 Xl | All versions |
Cisco Nexus 3548 X | All versions |
Cisco Nexus 3548 Xl | All versions |
Cisco Nexus 36180yc R | All versions |
Cisco Nexus 3636c R | All versions |
Cisco Nexus 9000v | All versions |
Cisco Nexus 92160yc X | All versions |
Cisco Nexus 9221c | All versions |
Cisco Nexus 92300yc | All versions |
Cisco Nexus 92304qc | All versions |
Cisco Nexus 92348gc X | All versions |
Cisco Nexus 9236c | All versions |
Cisco Nexus 9272q | All versions |
Cisco Nexus 93108tc Ex | All versions |
Cisco Nexus 93108tc Ex 24 | All versions |
Cisco Nexus 93108tc Fx | All versions |
Cisco Nexus 93108tc Fx 24 | All versions |
Cisco Nexus 93120tx | All versions |
Cisco Nexus 93128tx | All versions |
Cisco Nexus 9316d Gx | All versions |
Cisco Nexus 93180lc Ex | All versions |
Cisco Nexus 93180yc Ex | All versions |
Cisco Nexus 93180yc Ex 24 | All versions |
Cisco Nexus 93180yc Fx | All versions |
Cisco Nexus 93180yc Fx 24 | All versions |
Cisco Nexus 93180yc Fx3 | All versions |
Cisco Nexus 93180yc Fx3s | All versions |
Cisco Nexus 93216tc Fx2 | All versions |
Cisco Nexus 93240yc Fx2 | All versions |
Cisco Nexus 9332pq | All versions |
Cisco Nexus 93360yc Fx2 | All versions |
Cisco Nexus 9336c Fx2 | All versions |
Cisco Nexus 9336c Fx2 E | All versions |
Cisco Nexus 9336pq | All versions |
Cisco Nexus 9348gc Fxp | All versions |
Cisco Nexus 93600cd Gx | All versions |
Cisco Nexus 9364c | All versions |
Cisco Nexus 9364c Gx | All versions |
Cisco Nexus 9372px | All versions |
Cisco Nexus 9372px E | All versions |
Cisco Nexus 9372tx | All versions |
Cisco Nexus 9372tx E | All versions |
Cisco Nexus 9396px | All versions |
Cisco Nexus 9396tx | All versions |
Cisco Nexus 9508 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.3(8)n1(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Nexus 5548p | All versions |
Cisco Nexus 5548up | All versions |
Cisco Nexus 5596t | All versions |
Cisco Nexus 5596up | All versions |
Cisco Nexus 56128p | All versions |
Cisco Nexus 5624q | All versions |
Cisco Nexus 5648q | All versions |
Cisco Nexus 5672up | All versions |
Cisco Nexus 5672up 16g | All versions |
Cisco Nexus 5696q | All versions |
Cisco Nexus 6001 | All versions |
Cisco Nexus 6004 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0\(4i\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs 6248up | All versions |
Cisco Ucs 6296up | All versions |
Cisco Ucs 6324 | All versions |
Cisco Ucs 6332 | All versions |
Cisco Ucs 6332 16up | All versions |
Cisco Ucs 64108 | All versions |
Cisco Ucs 6454 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version r231 |
| Running on/with | Platform Versions |
|---|---|
Cisco Firepower 4110 | All versions |
Cisco Firepower 4112 | All versions |
Cisco Firepower 4115 | All versions |
Cisco Firepower 4120 | All versions |
Cisco Firepower 4125 | All versions |
Cisco Firepower 4140 | All versions |
Cisco Firepower 4145 | All versions |
Cisco Firepower 4150 | All versions |
Cisco Firepower 9300 | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.