CVE Feed

    Dashboard / CVE / CVE-2023-20089

    CVE-2023-20089

    A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due to incorrect error checking when parsing ingress LLDP packets. An attacker could exploit this vulnerability by sending a steady stream of crafted LLDP packets to an affected device. A successful exploit could allow the attacker to cause a memory leak, which could result in a denial of service (DoS) condition when the device unexpectedly reloads. Note: This vulnerability cannot be exploited by transit traffic through the device. The crafted LLDP packet must be targeted to a directly connected interface, and the attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). In addition, the attack surface for this vulnerability can be reduced by disabling LLDP on interfaces where it is not required.

    Published:Feb 23, 2023
    Last Modified:Nov 21, 2024
    EPS:Feb 23, 2023
    EPSS Score:0.00109
    CVSS Score:7.4

    Affected Products

    Vendor
    Cisco
    Product
    Nexus 9000v
    Vendor
    Cisco
    Product
    Nexus 92160yc-x
    Vendor
    Cisco
    Product
    Nexus 92300yc
    Vendor
    Cisco
    Product
    Nexus 92304qc
    Vendor
    Cisco
    Product
    Nexus 92348gc-x
    Vendor
    Cisco
    Product
    Nexus 9236c
    Vendor
    Cisco
    Product
    Nexus 9272q
    Vendor
    Cisco
    Product
    Nexus 93108tc-ex
    Vendor
    Cisco
    Product
    Nexus 93108tc-ex-24
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx-24
    Vendor
    Cisco
    Product
    Nexus 93108tc-fx3p
    Vendor
    Cisco
    Product
    Nexus 93120tx
    Vendor
    Cisco
    Product
    Nexus 93128tx
    Vendor
    Cisco
    Product
    Nexus 9316d-gx
    Vendor
    Cisco
    Product
    Nexus 93180lc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex
    Vendor
    Cisco
    Product
    Nexus 93180yc-ex-24
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx-24
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx3
    Vendor
    Cisco
    Product
    Nexus 93180yc-fx3s
    Vendor
    Cisco
    Product
    Nexus 93216tc-fx2
    Vendor
    Cisco
    Product
    Nexus 93240yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9332c
    Vendor
    Cisco
    Product
    Nexus 9332d-gx2b
    Vendor
    Cisco
    Product
    Nexus 9332pq
    Vendor
    Cisco
    Product
    Nexus 93360yc-fx2
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2
    Vendor
    Cisco
    Product
    Nexus 9336c-fx2-e
    Vendor
    Cisco
    Product
    Nexus 9336pq Aci Spine
    Vendor
    Cisco
    Product
    Nexus 9348d-gx2a
    Vendor
    Cisco
    Product
    Nexus 9348gc-fxp
    Vendor
    Cisco
    Product
    Nexus 93600cd-gx
    Vendor
    Cisco
    Product
    Nexus 9364c
    Vendor
    Cisco
    Product
    Nexus 9364c-gx
    Vendor
    Cisco
    Product
    Nexus 9364d-gx2a
    Vendor
    Cisco
    Product
    Nexus 9372px
    Vendor
    Cisco
    Product
    Nexus 9372px-e
    Vendor
    Cisco
    Product
    Nexus 9372tx
    Vendor
    Cisco
    Product
    Nexus 9372tx-e
    Vendor
    Cisco
    Product
    Nexus 9396px
    Vendor
    Cisco
    Product
    Nexus 9396tx
    Vendor
    Cisco
    Product
    Nexus 9408
    Vendor
    Cisco
    Product
    Nexus 9508
    Vendor
    Cisco
    Product
    Nexus 9808
    Vendor
    Cisco
    Product
    Nx-os

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High