Vulnslist

find the latest Cisco vulnerabilities

Cisco Nexus 9000 Series Fabric Switches ACI Mode Queue Wedge Denial of Service Vulnerability

cisco-sa-n9kaci-queue-wedge-cLDDEfKF · High · Published · Updated

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control plane traffic to the device being dropped. This could result in one or more leaf switches being removed from the fabric. This vulnerability is due to mishandling of ingress TCP traffic to a specific port. An attacker could exploit this vulnerability by sending a stream of TCP packets to a specific port on a Switched Virtual Interface (SVI) configured on the device. A successful exploit could allow the attacker to cause a specific packet queue to queue network buffers but never process them, leading to an eventual queue wedge. This could cause control plane traffic to be dropped, resulting in a denial of service (DoS) condition where the leaf switches are unavailable. Note: This vulnerability requires a manual intervention to power-cycle the device to recover. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9kaci-queue-wedge-cLDDEfKF This advisory is part of the August 2021 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: August 2021 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

A possible mitigation for this vulnerability is available for customers who cannot upgrade to a fixed release; however, it does not persist after each reload but can be used as a stopgap measure until the device can be upgraded. To coordinate implementation of the mitigation, contact the Cisco Technical Assistance Center (TAC) https://www.cisco.com/go/tac/ .

While this mitigation has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

CVEsCVE-2021-1523
Cisco Bug IDsCSCvx14142
CVSS ScoreBase 8.6
Base 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco NX-OS System Software in ACI Mode 13.2(1l), Cisco NX-OS System Software in ACI Mode 13.2(1m), Cisco NX-OS System Software in ACI Mode 13.2(2l), Cisco NX-OS System Software in ACI Mode 13.2(2o), Cisco NX-OS System Software in ACI Mode 13.2(3i), Cisco NX-OS System Software in ACI Mode 13.2(3n), Cisco NX-OS System Software in ACI Mode 13.2(3o), Cisco NX-OS System Software in ACI Mode 13.2(3r), Cisco NX-OS System Software in ACI Mode 13.2(4d), Cisco NX-OS System Software in ACI Mode 13.2(4e), Cisco NX-OS System Software in ACI Mode 13.2(3j), Cisco NX-OS System Software in ACI Mode 13.2(3s), Cisco NX-OS System Software in ACI Mode 13.2(5d), Cisco NX-OS System Software in ACI Mode 13.2(5e), Cisco NX-OS System Software in ACI Mode 13.2(5f), Cisco NX-OS System Software in ACI Mode 13.2(6i), Cisco NX-OS System Software in ACI Mode 13.2(41d), Cisco NX-OS System Software in ACI Mode 13.2(7f), Cisco NX-OS System Software in ACI Mode 13.2(7k), Cisco NX-OS System Software in ACI Mode 13.2(9b), Cisco NX-OS System Software in ACI Mode 13.2(8d), Cisco NX-OS System Software in ACI Mode 13.2(9f), Cisco NX-OS System Software in ACI Mode 13.2(9h), Cisco NX-OS System Software in ACI Mode 14.0(1h), Cisco NX-OS System Software in ACI Mode 14.0(2c), Cisco NX-OS System Software in ACI Mode 14.0(3d), Cisco NX-OS System Software in ACI Mode 14.0(3c), Cisco NX-OS System Software in ACI Mode 14.1(1i), Cisco NX-OS System Software in ACI Mode 14.1(1j), Cisco NX-OS System Software in ACI Mode 14.1(1k), Cisco NX-OS System Software in ACI Mode 14.1(1l), Cisco NX-OS System Software in ACI Mode 14.1(2g), Cisco NX-OS System Software in ACI Mode 14.1(2m), Cisco NX-OS System Software in ACI Mode 14.1(2o), Cisco NX-OS System Software in ACI Mode 14.1(2s), Cisco NX-OS System Software in ACI Mode 14.1(2u), Cisco NX-OS System Software in ACI Mode 14.1(2w), Cisco NX-OS System Software in ACI Mode 14.1(2x), Cisco NX-OS System Software in ACI Mode 14.2(1i), Cisco NX-OS System Software in ACI Mode 14.2(1j), Cisco NX-OS System Software in ACI Mode 14.2(1l), Cisco NX-OS System Software in ACI Mode 14.2(2e), Cisco NX-OS System Software in ACI Mode 14.2(2f), Cisco NX-OS System Software in ACI Mode 14.2(2g), Cisco NX-OS System Software in ACI Mode 14.2(3j), Cisco NX-OS System Software in ACI Mode 14.2(3l), Cisco NX-OS System Software in ACI Mode 14.2(3n), Cisco NX-OS System Software in ACI Mode 14.2(3q), Cisco NX-OS System Software in ACI Mode 14.2(4i), Cisco NX-OS System Software in ACI Mode 14.2(4k), Cisco NX-OS System Software in ACI Mode 14.2(4o), Cisco NX-OS System Software in ACI Mode 14.2(4p), Cisco NX-OS System Software in ACI Mode 14.2(5k), Cisco NX-OS System Software in ACI Mode 14.2(5l), Cisco NX-OS System Software in ACI Mode 14.2(5n), Cisco NX-OS System Software in ACI Mode 14.2(6d), Cisco NX-OS System Software in ACI Mode 14.2(6g), Cisco NX-OS System Software in ACI Mode 14.2(6h), Cisco NX-OS System Software in ACI Mode 14.2(6l), Cisco NX-OS System Software in ACI Mode 14.2(6o), Cisco NX-OS System Software in ACI Mode, Cisco Nexus 9000 Series Switches

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2021-1523 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2021-1523 Cisco OpenVuln
Cisco NX-OS Software CVE-2021-1523 Cisco OpenVuln
Cisco Firepower Extensible Operating System (FXOS) CVE-2021-1523 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2021-1523 Cisco OpenVuln
Cisco Nexus 9000 Series Switches CVE-2021-1523 Cisco OpenVuln
Cisco NX-OS System Software in ACI Mode CVE-2021-1523 Cisco OpenVuln