#VU50944 Cross-site request forgery in Cisco Systems, Inc products - CVE-2021-1227
Published: February 25, 2021
Cisco MDS 9000 Series Multilayer Switches
Cisco Nexus 3000 Series Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in the NX-API feature. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.