CVE Feed

    Dashboard / CVE / CVE-2019-1890

    CVE-2019-1890

    A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The vulnerability is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this vulnerability by sending a malicious LLDP packet on the adjacent subnet to the Cisco Nexus 9000 Series Switch in ACI mode. A successful exploit could allow the attacker to connect an unauthorized server to the infrastructure VLAN, which is highly privileged. With a connection to the infrastructure VLAN, the attacker can make unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or join other host endpoints.

    Published:Jul 4, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 4, 2019
    EPSS Score:0.00098
    CVSS Score:6.5

    Affected Products

    Vendor
    Cisco
    Product
    9432pq
    Vendor
    Cisco
    Product
    9536pq
    Vendor
    Cisco
    Product
    9636pq
    Vendor
    Cisco
    Product
    9736pq
    Vendor
    Cisco
    Product
    Application Policy Infrastructure Controller
    Vendor
    Cisco
    Product
    N9k-x9432c-s
    Vendor
    Cisco
    Product
    N9k-x9464px
    Vendor
    Cisco
    Product
    N9k-x9464tx2
    Vendor
    Cisco
    Product
    N9k-x9564px
    Vendor
    Cisco
    Product
    N9k-x9564tx
    Vendor
    Cisco
    Product
    N9k-x9636c-r
    Vendor
    Cisco
    Product
    N9k-x9636c-rx
    Vendor
    Cisco
    Product
    N9k-x97160yc-ex
    Vendor
    Cisco
    Product
    N9k-x9732c-ex
    Vendor
    Cisco
    Product
    N9k-x9732c-fx
    Vendor
    Cisco
    Product
    N9k-x9736c-ex
    Vendor
    Cisco
    Product
    N9k-x9736c-fx
    Vendor
    Cisco
    Product
    N9k-x9788tc-fx
    Vendor
    Cisco
    Product
    Nexus 92160yc-x
    Vendor
    Cisco
    Product
    Nexus 93108tc-ex
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx
    Vendor
    Cisco
    Product
    Nexus 93120tx
    Vendor
    Cisco
    Product
    Nexus 9316d-gx
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx
    Vendor
    Cisco
    Product
    Nexus 93216tc-fx2
    Vendor
    Cisco
    Product
    Nexus 93240yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9332c
    Vendor
    Cisco
    Product
    Nexus 93360yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2
    Vendor
    Cisco
    Product
    Nexus 9348gc-fxp
    Vendor
    Cisco
    Product
    Nexus 93600cd-gx
    Vendor
    Cisco
    Product
    Nexus 9364c
    Vendor
    Cisco
    Product
    X9636q-r

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High