CVE-2011-2581: Medium severity cisco nx-os vulnerability
The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending packets, aka Bug IDs CSCto09813 and CSCtr61490.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2581?
CVE-2011-2581 has been classified as a high severity vulnerability due to its potential to allow remote attackers to bypass access controls.
How do I fix CVE-2011-2581?
To fix CVE-2011-2581, you should upgrade your Cisco NX-OS to the latest version that addresses this vulnerability.
What versions of Cisco NX-OS are affected by CVE-2011-2581?
CVE-2011-2581 affects Cisco NX-OS versions 5.0(2) and 5.0(3) before 5.0(3)N2(1) for Nexus 5000 series switches and older versions for Nexus 3000 series.
Can CVE-2011-2581 be exploited remotely?
Yes, CVE-2011-2581 can be exploited remotely by attackers if they manipulate access control lists.
What is the impact of CVE-2011-2581?
The impact of CVE-2011-2581 includes unauthorized access, as it allows attackers to bypass intended access restrictions.