Memory leak in Cisco Nexus 9000 Series Switches in ACI Mode - CVE-2023-20089
Published: February 23, 2023
Vulnerability identifier: #VU72507
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20089
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack on the target system.
The vulnerability exists due memory leak in the Link Layer Discovery Protocol (LLDP) feature. A remote attacker on the local network can force the application to leak memory and perform denial of service attack.
Affected software
Cisco Nexus 9000 Series Switches in ACI Mode
How to mitigate CVE-2023-20089
Install updates from vendor's website.
Cisco Nexus 9000 Series Switches in ACI Mode - addressed in versions 10.3(2), 15.2(6e), 15.2(6g), 15.2(7f), 15.2(7g)