MEDIUM · 6.8

CVE-2019-1977

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cau...

Vulnerability Description

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.

CVSS Score

6.8

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoNx-Os12.3\(1h\)
CiscoNexus 9000-
CiscoNexus 93108Tc-Ex-
CiscoNexus 93108Tc-Fx-
CiscoNexus 93120Tx-
CiscoNexus 93128Tx-
CiscoNexus 93180Lc-Ex-
CiscoNexus 93180Yc-Ex-
CiscoNexus 93180Yc-Fx-
CiscoNexus 9332Pq-
CiscoNexus 9336C-Fx2-
CiscoNexus 9336Pq-
CiscoNexus 9348Gc-Fxp-
CiscoNexus 9364C-
CiscoNexus 9372Px-
CiscoNexus 9372Px-E-
CiscoNexus 9372Tx-
CiscoNexus 9372Tx-E-
CiscoNexus 9396Px-
CiscoNexus 9396Tx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1977?

CVE-2019-1977 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cau...

How severe is CVE-2019-1977?

CVE-2019-1977 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1977?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 9000, Cisco Nexus 93108Tc-Ex, Cisco Nexus 93108Tc-Fx, Cisco Nexus 93120Tx.