CVE-2021-1227: Cisco NX-OS Software NX-API Cross-Site Request Forgery Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1227?
CVE-2021-1227 is a vulnerability in the NX-API feature of Cisco NX-OS Software that could allow an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
What is the severity of CVE-2021-1227?
The severity of CVE-2021-1227 is high, with a severity score of 8.1.
Which software versions are affected by CVE-2021-1227?
Cisco NX-OS Software versions 8.4(2a), 8.4(3), and 8.4(3)s19 are affected by CVE-2021-1227.
How can an attacker exploit CVE-2021-1227?
An attacker can exploit CVE-2021-1227 by conducting a cross-site request forgery (CSRF) attack on an affected system.
Where can I find more information about CVE-2021-1227?
You can find more information about CVE-2021-1227 on the Cisco Security Advisory website.