Files or directories accessible to external parties in Cisco Systems, Inc products - CVE-2021-1361
Published: February 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the service at port 9075/tcp is incorrectly configured to listen and respond to external connection requests. A remote non-authenticated attacker can send specially crafted packets to port 9075/tcp and create, delete, or overwrite arbitrary files on the system with root privileges.
Successful exploitation of the vulnerability may results in a complete compromise of the affected system.
Affected software
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS
PowerFlex rack
How to mitigate CVE-2021-1361
Install updates from vendor's website.
This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software Release 9.3(5) or Release 9.3(6):
- Nexus 3000 Series Switches
- Nexus 9000 Series Switches in standalone NX-OS mode
PowerFlex rack - addressed in versions 3.3.10.0, 3.4.4.2, 3.5.4.2, 3.6.1.0