Database/Control plane, storage & DevOps
Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk its
Impact
A device plugged into a normal front-panel port can talk its way onto the ACI infrastructure VLAN — the fabric's own control plane. From there an attacker sees and can influence the fabric's internal signalling rather than one tenant's EPG. In a multi-tenant ACI build this is the boundary that separates 'a tenant' from 'the fabric operator'.
Who can reach it
Unauthenticated, adjacent — physical or logical access to a leaf front-panel port. Any tenant with a bare-metal node, or anyone who can plug into a rack, is in position.
What to do
ACI software upgrade across the APIC cluster and the leaf/spine switches — a staged fabric upgrade, not a single reload, and Cisco's recommended sequence takes hours on a large pod. Interim mitigation is strict port-level admission control and disabling unused ports, both live config changes.
References
Related entries
- HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear whenCVE-2021-45104 · HTCondor (daemon-to-daemon channel, negotiator/startd/schedd)High
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationCVE-2022-31671 · Harbor registryHigh
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedCVE-2022-35919 · MinIO (admin server-update API)High
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andCVE-2025-20111 · Cisco Nexus 3000/9000 (health monitoring diagnostics)High
- Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMSCVE-2026-15911 · Confluent Kafka Python client (HashiCorp Vault KMS integration)High
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.