Rewterz
Rewterz Threat Advisory – CVE-2021-27241 – Avast Premium Security denial of service
February 25, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-22681 – ICS: Rockwell Automation Logix Controllers security bypass
February 26, 2021

Rewterz Threat Advisory – CVE-2021-1368 – Cisco FXOS and NX-OS Software code execution

Severity

High

Analysis Summary

CVE-2021-1368

Cisco FXOS and NX-OS Software could allow a remote attacker to execute arbitrary code on the system, caused by improper input validation. By sending specially-crafted UDLD protocol packets, an attacker could exploit this vulnerability to execute arbitrary code with administrative privileges or cause the Cisco UDLD process to crash and restart multiple times, and results in a denial of service condition.

Impact

Gain access

Affected Vendors

Cisco

Affected Products

  • Cisco Nexus 3000 Series Switches
  • Cisco Nexus 7000 Series Switches

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information and complete list of affected products.

Cisco Security Advisory cisco-sa-nxos-udld-rce-xetH6w35