VDB
CVE-2021-1231
CVE-2021-1231
PUBLISHED
CVSS 4.699999809265137 MEDIUM
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP packet. An attacker could exploit this vulnerability by sending a crafted LLDP packet on an SFP interface to an affected device. A successful exploit could allow the attacker to disable switching on the SFP interface, which could disrupt network traffic.
EPSS 0.12% · 30.0th percentile
Risk Scores
CVSS 3.1
4.699999809265137
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
EPSS Score
0.12%
30.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | nx-os | 11.0\(1b\), 11.0\(1c\), 11.0\(1d\) |
| Cisco | Cisco NX-OS System Software in ACI Mode | * |
Exploit Intelligence
Timeline
- Feb 24, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score