A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.
2021-02-24T20:15:12.410
2024-11-21T05:43:52.533
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | nx-os | 8.4\(2a\) | Yes |
Operating System | cisco | nx-os | 8.4\(3\) | Yes |
Operating System | cisco | nx-os | 8.4\(3\)s19 | Yes |
Hardware | cisco | mds_9148s | - | No |
Hardware | cisco | mds_9250i | - | No |
Hardware | cisco | mds_9706 | - | No |
Hardware | cisco | mds_9710 | - | No |
Hardware | cisco | nexus_7000 | - | No |
Hardware | cisco | nexus_7700 | - | No |
Operating System | cisco | nx-os | 9.3\(3\)idi9\(0.569\) | Yes |
Hardware | cisco | nexus_3048 | - | No |
Hardware | cisco | nexus_31108pv-v | - | No |
Hardware | cisco | nexus_31108tc-v | - | No |
Hardware | cisco | nexus_31128pq | - | No |
Hardware | cisco | nexus_3132c-z | - | No |
Hardware | cisco | nexus_3132q-v | - | No |
Hardware | cisco | nexus_3132q-x | - | No |
Hardware | cisco | nexus_3132q-xl | - | No |
Hardware | cisco | nexus_3164q | - | No |
Hardware | cisco | nexus_3172pq | - | No |
Hardware | cisco | nexus_3172pq-xl | - | No |
Hardware | cisco | nexus_3232c | - | No |
Hardware | cisco | nexus_3264c-e | - | No |
Hardware | cisco | nexus_3264q | - | No |
Hardware | cisco | nexus_3408-s | - | No |
Hardware | cisco | nexus_34180yc | - | No |
Hardware | cisco | nexus_3432d-s | - | No |
Hardware | cisco | nexus_3464c | - | No |
Hardware | cisco | nexus_3524-x | - | No |
Hardware | cisco | nexus_3524-xl | - | No |
Hardware | cisco | nexus_3548-x | - | No |
Hardware | cisco | nexus_3548-xl | - | No |
Hardware | cisco | nexus_36180yc-r | - | No |
Hardware | cisco | nexus_3636c-r | - | No |
Hardware | cisco | nexus_9200 | - | No |
Hardware | cisco | nexus_9300 | - | No |
Hardware | cisco | nexus_9500 | - | No |
Operating System | cisco | nx-os | 7.3\(8\)n1\(0.809\) | Yes |
Hardware | cisco | nexus_5548p | - | No |
Hardware | cisco | nexus_5548up | - | No |
Hardware | cisco | nexus_5596t | - | No |
Hardware | cisco | nexus_5596up | - | No |
Hardware | cisco | nexus_56128p | - | No |
Hardware | cisco | nexus_5624q | - | No |
Hardware | cisco | nexus_5648q | - | No |
Hardware | cisco | nexus_5672up | - | No |
Hardware | cisco | nexus_5672up-16g | - | No |
Hardware | cisco | nexus_5696q | - | No |
Hardware | cisco | nexus_6001 | - | No |
Hardware | cisco | nexus_6004 | - | No |