CVE-2021-1590: Cisco NX-OS Software system login block-for Denial of Service Vulnerability
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when an attack is detected and acted upon. An attacker could exploit this vulnerability by performing a brute-force login attack on an affected device. A successful exploit could allow the attacker to cause a login process to reload, which could result in a delay during authentication to the affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1590?
CVE-2021-1590 has been rated as a high severity vulnerability due to its potential to cause a denial of service (DoS).
How do I fix CVE-2021-1590?
To fix CVE-2021-1590, update your Cisco NX-OS to the latest patched version as recommended by Cisco's advisory.
Which Cisco NX-OS versions are affected by CVE-2021-1590?
CVE-2021-1590 affects Cisco NX-OS versions 7.0(3)i4(0.116) and 7.3(7)n1(1b).
Is there any workaround for CVE-2021-1590?
No specific workaround is provided for CVE-2021-1590; applying the latest updates is the best course of action.
Can CVE-2021-1590 be exploited remotely?
Yes, CVE-2021-1590 can be exploited by an unauthenticated remote attacker.