Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20089


A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due to incorrect error checking when parsing ingress LLDP packets. An attacker could exploit this vulnerability by sending a steady stream of crafted LLDP packets to an affected device. A successful exploit could allow the attacker to cause a memory leak, which could result in a denial of service (DoS) condition when the device unexpectedly reloads. Note: This vulnerability cannot be exploited by transit traffic through the device. The crafted LLDP packet must be targeted to a directly connected interface, and the attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). In addition, the attack surface for this vulnerability can be reduced by disabling LLDP on interfaces where it is not required.


Published

2023-02-23T20:15:13.557

Last Modified

2024-11-21T07:40:31.967

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-789
  • Type: Primary
    CWE-401

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os 15.2\(1g\) Yes
Operating System cisco nx-os 15.2\(2e\) Yes
Operating System cisco nx-os 15.2\(2f\) Yes
Operating System cisco nx-os 15.2\(2g\) Yes
Operating System cisco nx-os 15.2\(2h\) Yes
Operating System cisco nx-os 15.2\(3e\) Yes
Operating System cisco nx-os 15.2\(3f\) Yes
Operating System cisco nx-os 15.2\(3g\) Yes
Operating System cisco nx-os 15.2\(4d\) Yes
Operating System cisco nx-os 15.2\(4e\) Yes
Operating System cisco nx-os 15.2\(4f\) Yes
Operating System cisco nx-os 15.2\(5c\) Yes
Operating System cisco nx-os 15.2\(5d\) Yes
Operating System cisco nx-os 15.2\(5e\) Yes
Operating System cisco nx-os 16.0\(1g\) Yes
Operating System cisco nx-os 16.0\(1j\) Yes
Hardware cisco nexus_9000v - No
Hardware cisco nexus_92160yc-x - No
Hardware cisco nexus_92300yc - No
Hardware cisco nexus_92304qc - No
Hardware cisco nexus_92348gc-x - No
Hardware cisco nexus_9236c - No
Hardware cisco nexus_9272q - No
Hardware cisco nexus_93108tc-ex - No
Hardware cisco nexus_93108tc-ex-24 - No
Hardware cisco nexus_93108tc-fx - No
Hardware cisco nexus_93108tc-fx-24 - No
Hardware cisco nexus_93108tc-fx3p - No
Hardware cisco nexus_93120tx - No
Hardware cisco nexus_93128tx - No
Hardware cisco nexus_9316d-gx - No
Hardware cisco nexus_93180lc-ex - No
Hardware cisco nexus_93180yc-ex - No
Hardware cisco nexus_93180yc-ex-24 - No
Hardware cisco nexus_93180yc-fx - No
Hardware cisco nexus_93180yc-fx-24 - No
Hardware cisco nexus_93180yc-fx3 - No
Hardware cisco nexus_93180yc-fx3s - No
Hardware cisco nexus_93216tc-fx2 - No
Hardware cisco nexus_93240yc-fx2 - No
Hardware cisco nexus_9332c - No
Hardware cisco nexus_9332d-gx2b - No
Hardware cisco nexus_9332pq - No
Hardware cisco nexus_93360yc-fx2 - No
Hardware cisco nexus_9336c-fx2 - No
Hardware cisco nexus_9336c-fx2-e - No
Hardware cisco nexus_9336pq_aci_spine - No
Hardware cisco nexus_9348d-gx2a - No
Hardware cisco nexus_9348gc-fxp - No
Hardware cisco nexus_93600cd-gx - No
Hardware cisco nexus_9364c - No
Hardware cisco nexus_9364c-gx - No
Hardware cisco nexus_9364d-gx2a - No
Hardware cisco nexus_9372px - No
Hardware cisco nexus_9372px-e - No
Hardware cisco nexus_9372tx - No
Hardware cisco nexus_9372tx-e - No
Hardware cisco nexus_9396px - No
Hardware cisco nexus_9396tx - No
Hardware cisco nexus_9408 - No
Hardware cisco nexus_9508 - No
Hardware cisco nexus_9808 - No

References