A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.
2019-08-30T09:15:20.553
2024-11-21T04:37:48.753
Modified
CVSSv3.0: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | nx-os | 12.3\(1h\) | Yes |
Operating System | cisco | nx-os | 13.1\(2m\) | Yes |
Operating System | cisco | nx-os | 13.1\(2o\) | Yes |
Operating System | cisco | nx-os | 13.1\(2p\) | Yes |
Hardware | cisco | nexus_9000 | - | No |
Hardware | cisco | nexus_93108tc-ex | - | No |
Hardware | cisco | nexus_93108tc-fx | - | No |
Hardware | cisco | nexus_93120tx | - | No |
Hardware | cisco | nexus_93128tx | - | No |
Hardware | cisco | nexus_93180lc-ex | - | No |
Hardware | cisco | nexus_93180yc-ex | - | No |
Hardware | cisco | nexus_93180yc-fx | - | No |
Hardware | cisco | nexus_9332pq | - | No |
Hardware | cisco | nexus_9336c-fx2 | - | No |
Hardware | cisco | nexus_9336pq | - | No |
Hardware | cisco | nexus_9348gc-fxp | - | No |
Hardware | cisco | nexus_9364c | - | No |
Hardware | cisco | nexus_9372px | - | No |
Hardware | cisco | nexus_9372px-e | - | No |
Hardware | cisco | nexus_9372tx | - | No |
Hardware | cisco | nexus_9372tx-e | - | No |
Hardware | cisco | nexus_9396px | - | No |
Hardware | cisco | nexus_9396tx | - | No |
Hardware | cisco | nexus_9504 | - | No |
Hardware | cisco | nexus_9508 | - | No |
Hardware | cisco | nexus_9516 | - | No |