Database/Firmware, BMC & network fabric
Cisco NX-OS (BGP MD5 authentication): TENANT ISOLATION: BGP MD5 authentication can be bypassed, so an attacker can
Impact
TENANT ISOLATION: BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP session with the switch without the shared key. In an EVPN fabric that means injecting routes — including type-2 and type-5 EVPN routes — which is exactly how you steer one tenant's traffic to a machine you control. The authentication you configured to prevent unauthorized peering simply does not hold.
Who can reach it
Unauthenticated, remote — an attacker that can reach TCP/179 on the switch and is permitted by the peer-group/neighbor configuration's address range.
What to do
NX-OS upgrade plus reload. Interim mitigation is control-plane policing plus tight neighbor prefix ACLs so only known peer addresses can open a session at all — live config changes. If you run EVPN, also verify no unexpected routes were learned before you patched.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.