GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk its

CVE-2021-1228Control plane, storage & DevOpscurated

Impact

A device plugged into a normal front-panel port can talk its way onto the ACI infrastructure VLAN — the fabric's own control plane. From there an attacker sees and can influence the fabric's internal signalling rather than one tenant's EPG. In a multi-tenant ACI build this is the boundary that separates 'a tenant' from 'the fabric operator'.

Who can reach it

Unauthenticated, adjacent — physical or logical access to a leaf front-panel port. Any tenant with a bare-metal node, or anyone who can plug into a rack, is in position.

What to do

ACI software upgrade across the APIC cluster and the leaf/spine switches — a staged fabric upgrade, not a single reload, and Cisco's recommended sequence takes hours on a large pod. Interim mitigation is strict port-level admission control and disabling unused ports, both live config changes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.