4.3

CVE-2021-1367

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an affected device. A successful exploit could allow the attacker to cause a traffic loop, resulting in a DoS condition.

Data is provided by the National Vulnerability Database (NVD)
CiscoNx-os Version9.3(5)
   CiscoNexus 9000v Switch Version-
   CiscoNexus 92160yc-x Switch Version-
   CiscoNexus 92300yc Switch Version-
   CiscoNexus 92304qc Switch Version-
   CiscoNexus 92348gc-x Switch Version-
   CiscoNexus 9236c Switch Version-
   CiscoNexus 9272q Switch Version-
   CiscoNexus 93108tc-ex-24 Switch Version-
   CiscoNexus 93108tc-ex Switch Version-
   CiscoNexus 93108tc-fx-24 Version-
   CiscoNexus 93108tc-fx Switch Version-
   CiscoNexus 93120tx Version-
   CiscoNexus 93128tx Version-
   CiscoNexus 9316d-gx Version-
   CiscoNexus 93180lc-ex Version-
   CiscoNexus 93180yc-ex Version-
   CiscoNexus 93180yc-ex-24 Version-
   CiscoNexus 93180yc-fx Version-
   CiscoNexus 93180yc-fx-24 Version-
   CiscoNexus 93180yc-fx3 Version-
   CiscoNexus 93180yc-fx3s Version-
   CiscoNexus 93216tc-fx2 Version-
   CiscoNexus 93240yc-fx2 Version-
   CiscoNexus 9332c Version-
   CiscoNexus 9332pq Version-
   CiscoNexus 93360yc-fx2 Version-
   CiscoNexus 9336c-fx2 Version-
   CiscoNexus 9336c-fx2-e Version-
   CiscoNexus 9336pq Version-
   CiscoNexus 9348gc-fxp Version-
   CiscoNexus 93600cd-gx Version-
   CiscoNexus 9364c Version-
   CiscoNexus 9364c-gx Version-
   CiscoNexus 9372px Version-
   CiscoNexus 9372px-e Version-
   CiscoNexus 9372tx Version-
   CiscoNexus 9372tx-e Version-
   CiscoNexus 9396px Version-
   CiscoNexus 9396tx Version-
   CiscoNexus 9504 Version-
   CiscoNexus 9508 Version-
   CiscoNexus 9516 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.417
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:N/I:N/A:P
psirt@cisco.com 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.