Database/Control plane, storage & DevOps
Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as root
Impact
Unauthenticated remote file write, read and delete as root on the switch, over a service that listens on the management interface by default. An attacker on the management network can drop a file, replace a config, or wipe the box without ever having a credential. This is the single worst pre-auth exposure in the Nexus line and it is a good argument for treating the switch management VLAN as production, not as 'internal'.
Who can reach it
Unauthenticated, remote — anything that can reach TCP/9075 on the switch's mgmt0 interface. No credentials required.
What to do
NX-OS image upgrade and switch reload. As a stopgap, an interface ACL on mgmt0 restricting the affected port materially reduces exposure and can be applied live with no reload. Rollout: one reload per switch, drain-and-patch per MLAG pair.
References
Related entries
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCVE-2021-27797 · Brocade Fabric OS (hard-coded credentials)Critical
- etcd: Authentication flaw via the debug functionCVE-2021-28235 · etcdCritical
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCVE-2021-31884 · Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllersCritical
- Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remoteCVE-2021-32974 · Moxa NPort IAW5000A-I/O serial device serverCritical
- Grafana: Unauthenticated access to snapshots via /api/snapshots/:keyCVE-2021-39226 · GrafanaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.