First published: Wed Feb 24 2021(Updated: )
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =8.4\(2a\) | |
Cisco NX-OS | =8.4\(3\) | |
Cisco NX-OS | =8.4\(3\)s19 | |
Cisco MDS 9148S | ||
Cisco MDS 9250i | ||
Cisco MDS 9706 Firmware | ||
Cisco MDS 9710 Firmware | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7700 series | ||
Cisco NX-OS | =9.3\(3\)idi9\(0.569\) | |
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 31108PV-V Firmware | ||
Cisco Nexus 31108TC-V Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132C-Z Firmware | ||
Cisco Nexus 3132Q-V Firmware | ||
Cisco Nexus 3132Q-X/3132Q-XL | ||
Cisco Nexus 3132Q-X/3132Q-XL | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172PQ/PQ-XL | ||
Cisco Nexus 3172PQ/PQ-XL | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264C-E Firmware | ||
Cisco Nexus 3264Q Firmware | ||
Cisco Nexus 3408-S Firmware | ||
Cisco Nexus 34180YC Firmware | ||
Cisco Nexus 3432D-S Firmware | ||
Cisco Nexus 3464C Firmware | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3524-x/xl | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 3548-X/XL | ||
Cisco Nexus 36180YC-R Firmware | ||
Cisco Nexus 3636C-R Firmware | ||
Cisco Nexus 9200 firmware | ||
Cisco Nexus 9300 Firmware | ||
Cisco Nexus 9500 firmware | ||
Cisco NX-OS | =7.3\(8\)n1\(0.809\) | |
Cisco Nexus 5548P Firmware | ||
Cisco Nexus 5548UP Firmware | ||
Cisco Nexus 5596T Firmware | ||
Cisco Nexus 5596UP Firmware | ||
Cisco Nexus 56128p Firmware | ||
Cisco Nexus 5624Q Firmware | ||
Cisco Nexus 5648q Firmware | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5672UP-16G Firmware | ||
Cisco Nexus 5696Q Firmware | ||
Cisco Nexus 6001 Firmware | ||
Cisco Nexus 6004 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1227 is a vulnerability in the NX-API feature of Cisco NX-OS Software that could allow an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
The severity of CVE-2021-1227 is high, with a severity score of 8.1.
Cisco NX-OS Software versions 8.4(2a), 8.4(3), and 8.4(3)s19 are affected by CVE-2021-1227.
An attacker can exploit CVE-2021-1227 by conducting a cross-site request forgery (CSRF) attack on an affected system.
You can find more information about CVE-2021-1227 on the Cisco Security Advisory website.