Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2021-1227

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.

  • Published: Feb 24, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-1227
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.1
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:N

CWEs:

Software From Fixed in
cisco / nx-os 8.4(2a) 8.4(2a).x
cisco / nx-os 8.4(3) 8.4(3).x
cisco / nx-os 8.4(3)s19 8.4(3)s19.x
cisco / nx-os 9.3(3)idi9(0.569) 9.3(3)idi9(0.569).x
cisco / nx-os 7.3(8)n1(0.809) 7.3(8)n1(0.809).x