GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic you

CVE-2018-0090Firmware, BMC & network fabriccurated

Impact

The ACL you put on the management interface is not enforced, so traffic you believe is being dropped reaches the switch's control plane anyway. Every 'we restricted the mgmt interface to the jump host' assumption becomes false. It does not by itself grant access, but it silently removes the compensating control that most operators rely on for every other switch CVE in this list.

Who can reach it

Unauthenticated, remote — any host with IP reachability to mgmt0, even one the ACL was supposed to block.

What to do

NX-OS upgrade plus reload. Do not treat management-interface ACLs as a substitute for real network segmentation — put the management interface on a physically or VRF-separated OOB network, which is a config/topology change and the durable fix.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.