CVE-2013-1209: Medium severity cisco nx-os vulnerability
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM packets, which allows remote attackers to disable packet-level encryption and integrity protection via crafted packets, aka Bug ID CSCud14710.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1209?
CVE-2013-1209 has a medium severity rating due to the potential risk of unauthorized access to communication between the Virtual Supervisor Module and Virtual Ethernet Module.
How do I fix CVE-2013-1209?
To fix CVE-2013-1209, update your Cisco NX-OS software to the latest version that addresses this vulnerability.
Which Cisco products are affected by CVE-2013-1209?
CVE-2013-1209 affects the Cisco NX-OS software running on Nexus 1000V devices.
What are the impacts of CVE-2013-1209?
The impact of CVE-2013-1209 includes the potential for remote attackers to disable packet-level encryption and integrity protection.
Is there a workaround for CVE-2013-1209?
There are no official workarounds for CVE-2013-1209; the recommended action is to apply the necessary software updates.