First published: Wed Feb 23 2022(Updated: )
A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker could exploit this vulnerability by sending a crafted stream of traffic through the device. A successful exploit could allow the attacker to cause BFD traffic to be dropped, resulting in BFD session flaps. BFD session flaps can cause route instability and dropped traffic, resulting in a denial of service (DoS) condition. This vulnerability applies to both IPv4 and IPv6 traffic.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Nx-os | >=7.0\(3\)i6\(2\)<=7.0\(3\)i7\(3\) | |
Cisco N9k-c92160yc-x | ||
Cisco N9k-c92300yc | ||
Cisco N9k-c92304qc | ||
Cisco N9k-c9232c | ||
Cisco N9k-c92348gc-x | ||
Cisco N9k-c9236c | ||
Cisco N9k-c9272q | ||
Cisco N9k-c93108tc-ex | ||
Cisco N9k-c93108tc-fx | ||
Cisco N9k-c9316d-gx | ||
Cisco N9k-c93180lc-ex | ||
Cisco N9k-c93180yc-ex | ||
Cisco N9k-c93180yc-fx | ||
Cisco N9k-c93180yc2-fx | ||
Cisco N9k-c93216tc-fx2 | ||
Cisco N9k-c93240yc-fx2 | ||
Cisco N9k-c9332c | ||
Cisco N9k-c93360yc-fx2 | ||
Cisco N9k-c9336c-fx2 | ||
Cisco N9k-c9348gc-fxp | ||
Cisco N9k-c93600cd-gx | ||
Cisco N9k-c9364c | ||
Cisco N9k-c9364c-gx | ||
Cisco Nx-os | >=7.0\(3\)i6\(2\)<=9.3\(8\) | |
Cisco Nx-os | >=10.1\(1\)<=10.2\(1\) | |
Cisco N9k-x97160yc-ex | ||
Cisco N9k-x97284yc-fx | ||
Cisco N9k-x9732c-ex | ||
Cisco N9k-x9732c-fx | ||
Cisco N9k-x9736c-ex | ||
Cisco N9k-x9736c-fx | ||
Cisco N9k-x9788tc-fx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-20623.
The severity of CVE-2022-20623 is high, with a severity value of 7.5.
Cisco NX-OS Software for Cisco Nexus 9000 Series Switches is affected by CVE-2022-20623.
An unauthenticated, remote attacker can exploit this vulnerability to cause BFD traffic to be dropped on an affected device.
Yes, Cisco has released a security advisory with mitigation details for CVE-2022-20623. Please refer to the advisory for more information.