First published: Thu Aug 29 2019(Updated: )
A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =12.3\(1h\) | |
Cisco NX-OS | =13.1\(2m\) | |
Cisco NX-OS | =13.1\(2o\) | |
Cisco NX-OS | =13.1\(2p\) | |
Cisco Nexus 9000 Firmware | ||
Cisco Nexus | ||
Cisco Nexus 93108TC-FX Switch | ||
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128 Firmware | ||
Cisco Nexus 93180LC-EX Switch | ||
Cisco Nexus 93180YC-EX-24 | ||
Cisco Nexus 93180YC-FX Firmware | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus 9336C-FX2 Firmware | ||
Cisco Nexus N9336PQ | ||
Cisco Nexus 9348GC-FXP Firmware | ||
Cisco Nexus 9364c-h1 | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372PX-E Firmware | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9372TX-E Switch | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9504 firmware | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-1977.
The severity of CVE-2019-1977 is high with a CVSS score of 7.5.
The affected software for CVE-2019-1977 is Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode.
CVE-2019-1977 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances.
There is currently no fix available for CVE-2019-1977, but Cisco has provided mitigations in their advisory.