Cisco Security Advisory
Follow
Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability
A vulnerability exists in the PIM6 feature of certain Cisco Nexus switches.
This flaw could permit a remote attacker to cause a denial of service.
The attacker needs to be authenticated and have low privileges to exploit this.
Improper processing of PIM6 ephemeral data queries is the root cause.
Attackers can send crafted ephemeral queries via various programmatic interfaces.
These interfaces include NX-API REST, NETCONF, RESTConf, gRPC, and Model Driven Telemetry.
A successful exploit will crash and restart the PIM6 process.
This can lead to adjacency flaps and impact PIM6 and ephemeral query functions.
Software updates have been released by Cisco to fix this issue.
There are no available workarounds to mitigate this vulnerability.