#VU50944 Cross-site request forgery in Cisco Systems, Inc products - CVE-2021-1227

 

#VU50944 Cross-site request forgery in Cisco Systems, Inc products - CVE-2021-1227

Published: February 25, 2021


Vulnerability identifier: #VU50944
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1227
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco MDS 9000 Series Multilayer Switches
Cisco Nexus 3000 Series Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin in the NX-API feature. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Remediation

Install update from vendor's website.

External links