Database/Firmware, BMC & network fabric
Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic you
Impact
The ACL you put on the management interface is not enforced, so traffic you believe is being dropped reaches the switch's control plane anyway. Every 'we restricted the mgmt interface to the jump host' assumption becomes false. It does not by itself grant access, but it silently removes the compensating control that most operators rely on for every other switch CVE in this list.
Who can reach it
Unauthenticated, remote — any host with IP reachability to mgmt0, even one the ACL was supposed to block.
What to do
NX-OS upgrade plus reload. Do not treat management-interface ACLs as a substitute for real network segmentation — put the management interface on a physically or VRF-separated OOB network, which is a config/topology change and the durable fix.
References
Related entries
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerCVE-2018-1211 · Dell iDRAC7 / iDRAC8 (web server URI parser)High
- Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceCVE-2018-5254 · Arista EOS (BGP UPDATE)High
- Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentCVE-2019-18948 · Arista EOS (VxLAN agent)High
- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationCVE-2019-6193 · Lenovo XClarity Administrator (LXCA) - unauthenticated config file accessHigh
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionCVE-2020-11487 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): Default SNMP community strings on the DGX BMCCVE-2020-11489 · NVIDIA DGX BMC (AMI firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.