CVE-2021-1231: Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1231?
CVE-2021-1231 has been rated as high severity due to the potential for unauthenticated attackers to disrupt network services.
How do I fix CVE-2021-1231?
To fix CVE-2021-1231, update to the latest version of Cisco NX-OS that addresses the vulnerability.
Who is affected by CVE-2021-1231?
CVE-2021-1231 affects several versions of Cisco NX-OS running on Nexus 9000 Series Fabric Switches in ACI mode.
What kind of attacks can exploit CVE-2021-1231?
CVE-2021-1231 can be exploited by an unauthenticated, adjacent attacker to disable switching on affected SFP interfaces.
When was CVE-2021-1231 disclosed?
CVE-2021-1231 was disclosed in 2021 as part of Cisco's security advisory.