Database/Control plane, storage & DevOps
Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI mode
Impact
A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI mode gives an adjacent unauthenticated attacker denial of service or arbitrary code execution with root privileges on the switch. In ACI, LLDP is not optional — it is how the fabric discovers and validates its own topology — so you cannot simply turn it off the way you can on a standalone NX-OS leaf.
Who can reach it
Unauthenticated, adjacent — a crafted LLDP frame from a device on a leaf port.
What to do
ACI software upgrade across the fabric (APIC plus switches), staged. There is no good config workaround because ACI depends on LLDP; the compensating control is strict physical and port-admission control on leaf front-panel ports. Related memory-leak issue in the same subsystem: CVE-2023-20089.
References
Related entries
- IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsCVE-2019-4715 · IBM Spectrum Scale management GUIHigh
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapCVE-2020-12138 · AMD ATI atillk64.sys - physical memory mapping driverHigh
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateCVE-2020-12347 · Intel Data Center Manager ConsoleHigh
- Marvell QConvergeConsole (QLogic adapter management): Remote code execution on QConvergeConsole, the managementCVE-2020-17389 · Marvell QConvergeConsole (QLogic adapter management)High
- Ceph CephX authentication protocol: CephX does not correctly bind client identity, so an attacker who can captureCVE-2020-25660 · Ceph CephX authentication protocolHigh
- APC PowerChute Business Edition (v9.0.x and earlier): PowerChute runs the shutdown script that fires when a UPS reportsCVE-2020-7526 · APC PowerChute Business Edition (v9.0.x and earlier)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.