Database/Control plane, storage & DevOps
Cisco IOS XE MACsec Key Agreement (MKA over EAP-TLS): A logic error in MKA over EAP-TLS lets an unauthenticated
Impact
A logic error in MKA over EAP-TLS lets an unauthenticated adjacent attacker bypass authentication and pass traffic through a Layer 3 interface. MACsec here is doing double duty as link encryption and as port admission control, and both fail — an unauthenticated device on the wire gets its traffic forwarded as though it had authenticated.
Who can reach it
Unauthenticated attacker with adjacent (same-link) access to an interface configured for MKA with EAP-TLS.
What to do
Software upgrade plus device reload. Do not treat MACsec/MKA as your only port-admission control — pair it with per-port VLAN pinning and MAC allowlisting, which are live config changes that keep an unauthenticated device from reaching anything useful even when the MKA check fails.
References
Related entries
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupCVE-2021-23214 · PostgreSQLHigh
- tcmu-runner 1.3.x - 1.5.2 (userspace backstore handler for the Linux LIO target, used by Ceph iSCSI gateways and otherCVE-2021-3139 · tcmu-runner 1.3.x - 1.5.2High
- ClickHouse: Attacker-controlled offset in the LZ4 codecCVE-2021-42387 · ClickHouseHigh
- ClickHouse: Second heap out-of-bounds read in LZ4::decompressImpl reachable from a client queryCVE-2021-42388 · ClickHouseHigh
- HTCondor (condor_schedd, condor_collector): A user with nothing more than READ access to the schedd or collector canCVE-2021-45101 · HTCondor (condor_schedd, condor_collector)High
- HTCondor (S3 file transfer, daemon logs and job ClassAds): Pre-signed S3 URLs for a job's input and output are writtenCVE-2021-45103 · HTCondor (S3 file transfer, daemon logs and job ClassAds)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.