Database/Firmware, BMC & network fabric
Cisco NX-OS (BGP MD5 authentication): BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP session
Impact
BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP session with the switch without the shared key. In an EVPN fabric that means injecting routes — including type-2 and type-5 EVPN routes — which is exactly how you steer one tenant's traffic to a machine you control. The authentication you configured to prevent unauthorized peering simply does not hold.
Who can reach it
Unauthenticated, remote — an attacker that can reach TCP/179 on the switch and is permitted by the peer-group/neighbor configuration's address range.
What to do
NX-OS upgrade plus reload. Interim mitigation is control-plane policing plus tight neighbor prefix ACLs so only known peer addresses can open a session at all — live config changes. If you run EVPN, also verify no unexpected routes were learned before you patched.
References
Related entries
- Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS passwordCVE-2021-21522 · Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS password via the…High
- Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverCVE-2021-33627 · Insyde InsydeH2O (FwBlockServiceSmm)High
- InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSCVE-2021-38489 · InsydeH2O UEFI firmware (HDD password stored in a UEFI variable)High
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedCVE-2022-28735 · GRUB2 (shim_lock verifier)High
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderCVE-2022-28737 · shim (handle_image PE loader)High
- Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyCVE-2022-29275 · Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.