CVE-2021-1231
published 2021-02-24CVE-2021-1231: A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow…
PriorityP422medium4.7CVSS 3.1
AVAACLPRNUINSCCNINAL
EPSS
0.24%
15.7th percentile
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
Affected
167 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | nexus_9000_series_fabric_switches_aci_mode_link_layer_discovery_protocol_port | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2023-1231
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1231 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1231
Stable Channel Update for Desktop
CVE-2023-1231: Inappropriate implementation in Autofill. Reported by Kirtikumar Anandrao Ramchandani via Yan Zhu of Brave on 2021-11-30 [$3000][ 813542 ] Low CVE-2023-2314: Insufficient data validation in DevTools
Reported by Rob Wu on 2018-02-19 [$2000][ 1346924 ] Low CVE-2023-1232: Insufficient policy enforcement in Resource Timing
Severity: medium
Cisco
Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
vendor_cisco·2021-02-24·CVSS 4.7
CVE-2021-1231 [MEDIUM] CWE-284 Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface.
This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
Cisco has released software updates that address this vulnerability. There
Cisco
Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1231 Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
CVE-2021-1231: Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic. Cisco has released software updates that address this vulnerab
GHSA
GHSA-hpqm-fqwv-8ffg: A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode cou
ghsa_unreviewed·2022-05-24
CVE-2021-1231 [MEDIUM] CWE-284 GHSA-hpqm-fqwv-8ffg: A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode cou
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station
blogs_talos·2021-05-24·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station
Carl Hurd and Kelly Leuschner of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered multiple vulnerabilities in Trend Micro’s Home Network Security Station.
The Home Network Security Station is a device that monitors and protects home networks from security threats and provides other network management features. The Security Station can scan for vulnerabilities, detect and prevent possible intrusions and allow the user to control access settings for all devices on the network. TALOS-2021-1230 (CVE-2021-32457) and TALOS-2021-1231 (CVE-2021-32458) are elevation of privilege vulnerabilities that could allow an attacker to elevate their permissions on the targeted device. Another vulnerability, TALOS-2021-1241 (CVE-2021-32459), exists within a set
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station
blogs_talos·2021-05-24·CVSS 7.8
[HIGH] Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station
## Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station
Carl Hurd and Kelly Leuschner of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered multiple vulnerabilities in Trend Micro’s Home Network Security Station.
The Home Network Security Station is a device that monitors and protects home networks from security threats and provides other network management features. The Security Station can scan for vulnerabilities, detect and prevent possible intrusions and allow the user to control access settings for all devices on the network. TALOS-2021-1230 (CVE-2021-32457) and TALOS-2021-1231 (CVE-2021-32458) are elevation of privilege vulnerabilities that could allow an attacker to elevate their permissions o
2021-02-24
Published