Cisco NX-OS Software Control Plane Denial of Service Vulnerability
A Cisco NX-OS rate-limiting flaw lets remote attackers temporarily disrupt control-plane protocols with heavy traffic.
Cisco disclosed a denial-of-service vulnerability in NX-OS Software caused by rate limiting being improperly applied to some protocols. An unauthenticated remote attacker can send a high rate of UDP or TCP connections to a data-plane interface, exhausting resources and disrupting routing and control-plane protocols. Cisco says the condition clears without manual intervention once the traffic stops.
- Improper rate limiting lets remote attackers exhaust NX-OS resources.
- High-rate UDP or TCP traffic to a data-plane interface causes instability.
- Routing and control-plane protocols can suffer temporary packet loss.
- The denial of service clears after the traffic flood stops.
A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane protocols through some packet loss and temporary disruptions, causing a DoS condition. This DoS condition will clear without manual intervention soon after the high rate of traffic is stopped. Cisco…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.