Cisco Nexus 3000 and 9000 Seri... Note

Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability

A vulnerability affects Cisco Nexus 3000 and 9000 Series Switches operating in standalone NX-OS mode. The enforce-first-as feature of the Border Gateway Protocol (BGP) is implicated in this issue. An unauthenticated, remote attacker can exploit this flaw. The vulnerability stems from incorrect parsing of a transitive BGP attribute. By sending a specially crafted BGP update, an attacker can trigger BGP peer flaps. This disruption leads to a denial of service (DoS) condition. The crafted update is sent through an established BGP peer session. If an affected device receives this update, it will drop the BGP session. Consequently, the device will flap with the peer forwarding the malicious update. Cisco has released software updates to resolve this vulnerability and offers workarounds.