Memory leak in Cisco Nexus 9000 Series Switches in ACI Mode - CVE-2023-20089

 

Memory leak in Cisco Nexus 9000 Series Switches in ACI Mode - CVE-2023-20089

Published: February 23, 2023


Vulnerability identifier: #VU72507
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20089
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack on the target system.

The vulnerability exists due memory leak in the Link Layer Discovery Protocol (LLDP) feature. A remote attacker on the local network can force the application to leak memory and perform denial of service attack.


Affected software

Cisco Nexus 9000 Series Switches in ACI Mode

How to mitigate CVE-2023-20089

Install updates from vendor's website.

Cisco Nexus 9000 Series Switches in ACI Mode - addressed in versions 10.3(2), 15.2(6e), 15.2(6g), 15.2(7f), 15.2(7g)

External References

Related Security Bulletins