#VU50933 Files or directories accessible to external parties in Cisco Systems, Inc products - CVE-2021-1361
Published: February 24, 2021
Cisco NX-OS
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the service at port 9075/tcp is incorrectly configured to listen and respond to external connection requests. A remote non-authenticated attacker can send specially crafted packets to port 9075/tcp and create, delete, or overwrite arbitrary files on the system with root privileges.
Successful exploitation of the vulnerability may results in a complete compromise of the affected system.
Remediation
Install updates from vendor's website.
This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software Release 9.3(5) or Release 9.3(6):
- Nexus 3000 Series Switches
- Nexus 9000 Series Switches in standalone NX-OS mode