First published: Wed Aug 25 2021(Updated: )
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =7.0\(3\)i7\(9\) | |
Cisco NX-OS | =8.4\(1\) | |
Cisco NX-OS | =9.3\(7\) | |
Cisco Nexus 3000 | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 31108PC-V Firmware | ||
Cisco Nexus 31108TC-V Firmware | ||
Cisco Nexus 31128PQ | ||
Cisco Nexus 3132C-Z Firmware | ||
Cisco Nexus 3132Q-V Firmware | ||
Cisco Nexus 3132Q-X/3132Q-XL | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172PQ/PQ-XL | ||
Cisco Nexus 3172TQ-XL Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3264C-E Firmware | ||
Cisco Nexus 3264Q Firmware | ||
Cisco Nexus 3408-S Firmware | ||
Cisco Nexus 34180YC Firmware | ||
Cisco Nexus 3432D-S Firmware | ||
Cisco Nexus 3464C Firmware | ||
Cisco Nexus 3524-x/xl | ||
Cisco Nexus 3548-x/xl | ||
Cisco Nexus 36180YC-R Firmware | ||
Cisco Nexus 3636C-R Firmware | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware | ||
Cisco NX-OS Nexus 9000 Series | ||
Cisco Nexus 92160YC Switch | ||
Cisco Nexus 92300YC Firmware | ||
Cisco Nexus 92304QC Switch | ||
Cisco Nexus 92348GC-X Switch | ||
Cisco Nexus 9236C Switch | ||
Cisco Nexus 9272Q Switch | ||
Cisco Nexus | ||
Cisco Nexus 93108TC-EX-24 Firmware | ||
Cisco Nexus 93108TC-FX Switch | ||
Cisco Nexus 93108TC-FX Switch | ||
Cisco Nexus 93108TC-FX3P Firmware | ||
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128 Firmware | ||
Cisco Nexus 9316D-GX Firmware | ||
Cisco Nexus 93180LC-EX Switch | ||
Cisco Nexus 93180YC-EX-24 | ||
Cisco Nexus 93180YC-EX-24 Firmware | ||
Cisco Nexus 93180YC-FX Firmware | ||
Cisco Nexus 93180YC-FX-24 Firmware | ||
Cisco Nexus 93180YC-FX3 Firmware | ||
Cisco Nexus 93180YC-FX3S Firmware | ||
Cisco Nexus 93216TC-FX2 Firmware | ||
Cisco Nexus 93240YC-FX2 Firmware | ||
Cisco Nexus 9332C Firmware | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus 93360YC-FX2 | ||
Cisco Nexus 9336C-FX2 Firmware | ||
Cisco Nexus 9336C-FX2-E Firmware | ||
Cisco Nexus 9348GC-FXP Firmware | ||
Cisco Nexus 93600CD-GX Firmware | ||
Cisco Nexus 9364c-h1 | ||
Cisco Nexus 9364C-GX Firmware | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372PX-E Firmware | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9372TX-E Switch | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9508 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1588 has a high severity rating as it can allow unauthenticated remote attackers to cause a denial of service condition.
To fix CVE-2021-1588, upgrade to a Cisco NX-OS version that is not affected by the vulnerability, as outlined in Cisco's security advisory.
CVE-2021-1588 affects Cisco NX-OS 7.0(3)i7(9), 8.4(1), and 9.3(7).
No, CVE-2021-1588 can only be exploited remotely by unauthenticated attackers.
The potential impact of CVE-2021-1588 is a denial of service, which may render affected devices unreachable.