MEDIUM · 5.8

CVE-2021-1591

A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are confi...

Vulnerability Description

A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of resources that occurs when applying ACLs to port channel interfaces. An attacker could exploit this vulnerability by attempting to access network resources that are protected by the ACL. A successful exploit could allow the attacker to access network resources that would be protected by the ACL that was applied on the port channel interface.

CVSS Score

5.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CiscoNx-Os9.3\(4\)
CiscoNexus 9500 16-Slot-
CiscoNexus 9500 4-Slot-
CiscoNexus 9500 8-Slot-
CiscoNexus 9504-
CiscoNexus 9508-
CiscoNexus 9516-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1591?

CVE-2021-1591 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are confi...

How severe is CVE-2021-1591?

CVE-2021-1591 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1591?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 9500 16-Slot, Cisco Nexus 9500 4-Slot, Cisco Nexus 9500 8-Slot, Cisco Nexus 9504.