CVE Feed

    Dashboard / CVE / CVE-2021-1230

    CVE-2021-1230

    A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denial of service (DoS) condition. This vulnerability is due to an issue with the installation of routes upon receipt of a BGP update. An attacker could exploit this vulnerability by sending a crafted BGP update to an affected device. A successful exploit could allow the attacker to cause the routing process to crash, which could cause the device to reload. This vulnerability applies to both Internal BGP (IBGP) and External BGP (EBGP). Note: The Cisco implementation of BGP accepts incoming BGP traffic from explicitly configured peers only. To exploit this vulnerability, an attacker would need to send a specific BGP update message over an established TCP connection that appears to come from a trusted BGP peer.

    Published:Feb 24, 2021
    Last Modified:Nov 21, 2024
    EPS:Feb 24, 2021
    EPSS Score:0.00701
    CVSS Score:8.6

    Affected Products

    Vendor
    Cisco
    Product
    Nexus 9000v
    Vendor
    Cisco
    Product
    Nexus 92160yc-x
    Vendor
    Cisco
    Product
    Nexus 92300yc
    Vendor
    Cisco
    Product
    Nexus 92304qc
    Vendor
    Cisco
    Product
    Nexus 92348gc-x
    Vendor
    Cisco
    Product
    Nexus 9236c
    Vendor
    Cisco
    Product
    Nexus 9272q
    Vendor
    Cisco
    Product
    Nexus 93108tc-ex
    Vendor
    Cisco
    Product
    Nexus 93108tc-ex-24
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx-24
    Vendor
    Cisco
    Product
    Nexus 93120tx
    Vendor
    Cisco
    Product
    Nexus 93128tx
    Vendor
    Cisco
    Product
    Nexus 9316d-gx
    Vendor
    Cisco
    Product
    Nexus 93180lc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex-24
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx-24
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx3
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx3s
    Vendor
    Cisco
    Product
    Nexus 93216tc-fx2
    Vendor
    Cisco
    Product
    Nexus 93240yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9332c
    Vendor
    Cisco
    Product
    Nexus 9332pq
    Vendor
    Cisco
    Product
    Nexus 93360yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2-e
    Vendor
    Cisco
    Product
    Nexus 9336pq Aci Spine
    Vendor
    Cisco
    Product
    Nexus 9348gc-fxp
    Vendor
    Cisco
    Product
    Nexus 93600cd-gx
    Vendor
    Cisco
    Product
    Nexus 9364c
    Vendor
    Cisco
    Product
    Nexus 9364c-gx
    Vendor
    Cisco
    Product
    Nexus 9372px
    Vendor
    Cisco
    Product
    Nexus 9372px-e
    Vendor
    Cisco
    Product
    Nexus 9372tx
    Vendor
    Cisco
    Product
    Nexus 9372tx-e
    Vendor
    Cisco
    Product
    Nexus 9396px
    Vendor
    Cisco
    Product
    Nexus 9396tx
    Vendor
    Cisco
    Product
    Nexus 9508
    Vendor
    Cisco
    Product
    Nx-os

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High