CVE-2019-18998

Current Description

A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The vulnerability is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this vulnerability by sending a malicious LLDP packet on the adjacent subnet to the Cisco Nexus 9000 Series Switch in ACI mode. A successful exploit could allow the attacker to connect an unauthorized server to the infrastructure VLAN, which is highly privileged. With a connection to the infrastructure VLAN, the attacker can make unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or join other host endpoints.

Basic Data

PublishedJuly 04, 2019
Last ModifiedOctober 09, 2019
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-284
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:A/AC:L/Au:N/C:N/I:P/A:N
CVSS 2 - Access VectorADJACENT_NETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactNONE
CVSS 2 - Base Score3.3
SeverityLOW
Exploitability Score6.5
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

CVSS 3 - Version3.0
CVSS 3 - Vector StringCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 3 - Attack VectorADJACENT_NETWORK
CVSS 3 - Attack ComplexityLOW
CVSS 3 - Privileges RequiredNONE
CVSS 3 - User InteractionNONE
CVSS 3 - ScopeUNCHANGED
CVSS 3 - Confidentiality ImpactNONE
CVSS 3 - Integrity ImpactHIGH
CVSS 3 - Availability ImpactNONE
CVSS 3 - Base Score6.5
CVSS 3 - Base SeverityMEDIUM
Exploitability Score2.8
Base SeverityMEDIUM

Configurations

  • AND
    • OR - Configuration 1
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3ApplicationCiscoApplication Policy Infrastructure Controller7.3(0)zn(0.113)*******
    • OR Running on/with:
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3HardwareCisco9432pq-*******
      2.3HardwareCisco9536pq-*******
      2.3HardwareCisco9636pq-*******
      2.3HardwareCisco9736pq-*******
      2.3HardwareCiscoN9k-x9432c-s-*******
      2.3HardwareCiscoN9k-x9464px-*******
      2.3HardwareCiscoN9k-x9464tx2-*******
      2.3HardwareCiscoN9k-x9564px-*******
      2.3HardwareCiscoN9k-x9564tx-*******
      2.3HardwareCiscoN9k-x9636c-r-*******
      2.3HardwareCiscoN9k-x9636c-rx-*******
      2.3HardwareCiscoN9k-x97160yc-ex-*******
      2.3HardwareCiscoN9k-x9732c-ex-*******
      2.3HardwareCiscoN9k-x9732c-fx-*******
      2.3HardwareCiscoN9k-x9736c-ex-*******
      2.3HardwareCiscoN9k-x9736c-fx-*******
      2.3HardwareCiscoN9k-x9788tc-fx-*******
      2.3HardwareCiscoNexus 92160yc-x-*******
      2.3HardwareCiscoNexus 93108tc-ex-*******
      2.3HardwareCiscoNexus 93108tc-fx-*******
      2.3HardwareCiscoNexus 93120tx-*******
      2.3HardwareCiscoNexus 9316d-gx-*******
      2.3HardwareCiscoNexus 93180yc-ex-*******
      2.3HardwareCiscoNexus 93180yc-fx-*******
      2.3HardwareCiscoNexus 93216tc-fx2-*******
      2.3HardwareCiscoNexus 93240yc-fx2-*******
      2.3HardwareCiscoNexus 9332c-*******
      2.3HardwareCiscoNexus 93360yc-fx2-*******
      2.3HardwareCiscoNexus 9336c-fx2-*******
      2.3HardwareCiscoNexus 9348gc-fxp-*******
      2.3HardwareCiscoNexus 93600cd-gx-*******
      2.3HardwareCiscoNexus 9364c-*******
      2.3HardwareCiscoX9636q-r-*******

Vulnerable Software List

VendorProductVersions
Cisco Application Policy Infrastructure Controller 7.3(0)zn(0.113)

References

NameSourceURLTags
109052http://www.securityfocus.com/bid/109052BIDThird Party Advisory VDB Entry
20190703 Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerabilityhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypasCISCOVendor Advisory