A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Mds 9148s
Subscribe
Mds 9250i
Subscribe
Mds 9706
Subscribe
Mds 9710
Subscribe
Nexus 3048
Subscribe
Nexus 31108pv-v
Subscribe
Nexus 31108tc-v
Subscribe
Nexus 31128pq
Subscribe
Nexus 3132c-z
Subscribe
Nexus 3132q-v
Subscribe
Nexus 3132q-x
Subscribe
Nexus 3132q-xl
Subscribe
Nexus 3164q
Subscribe
Nexus 3172pq
Subscribe
Nexus 3172pq-xl
Subscribe
Nexus 3232c
Subscribe
Nexus 3264c-e
Subscribe
Nexus 3264q
Subscribe
Nexus 3408-s
Subscribe
Nexus 34180yc
Subscribe
Nexus 3432d-s
Subscribe
Nexus 3464c
Subscribe
Nexus 3524-x
Subscribe
Nexus 3524-xl
Subscribe
Nexus 3548-x
Subscribe
Nexus 3548-xl
Subscribe
Nexus 36180yc-r
Subscribe
Nexus 3636c-r
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5624q
Subscribe
Nexus 5648q
Subscribe
Nexus 5672up
Subscribe
Nexus 5672up-16g
Subscribe
Nexus 5696q
Subscribe
Nexus 6001
Subscribe
Nexus 6004
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nexus 9200
Subscribe
Nexus 9300
Subscribe
Nexus 9500
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-6694 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 Nov 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-08T23:40:13.499Z
Reserved: 2020-11-13T00:00:00
Link: CVE-2021-1227
Updated: 2024-08-03T16:02:56.336Z
Status : Modified
Published: 2021-02-24T20:15:12.410
Modified: 2024-11-21T05:43:52.533
Link: CVE-2021-1227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD