iTnews Asia
  • Home
  • News
  • Networking

Cisco not patching Nexus switch vulnerability

Cisco not patching Nexus switch vulnerability

Broken encryption.

By Richard Chirgwin on Jul 7, 2023 11:03AM

Cisco has disclosed a serious vulnerability in the encryption used in some of its Nexus 9000 switches, but said the bug will not be fixed.

“A vulnerability in the Cisco ACI [application-centric infrastructure] multi-site CloudSec encryption feature of Cisco Nexus 9000 Series fabric switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic,” Cisco’s advisory states.

The impact is that an attacker on the path between ACI sites could intercept encrypted traffic, apply cryptanalysis to break the encryption, and “read or modify” traffic transmitted between two sites.

The bug is present in Cisco Nexus 9332C and Nexus 9364C switches and the Cisco Nexus N9K-X9736C-FX line card, and the advisory says encryption on these devices should be turned off.

However, this vulnerability, which is rated High with a CVSS score of 7.4, will not be fixed.

“Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability”, the company stated.

“Customers who are currently using the Cisco ACI multi-site CloudSec encryption feature for the Cisco Nexus 9332C and Nexus 9364C switches and the Cisco Nexus N9K-X9736C-FX line card are advised to disable it and to contact their support organisation to evaluate alternative options.”

Since there’s no fix available, affected units will presumably have to be replaced.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco networking nexus security

Related Articles

  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
  • Cybersecurity threats CISOs should be most worried about in 2025
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Shangri-La Group's Jen hotels implement smart check-in kiosks

Shangri-La Group's Jen hotels implement smart check-in kiosks

Malaysia's digital super highway fibre network gets gear boost

Malaysia's digital super highway fibre network gets gear boost

Sime Darby to partner Equinix for digital transformation

Sime Darby to partner Equinix for digital transformation

Philippines internet exchange GetaFIX lands connection to Singapore

Philippines internet exchange GetaFIX lands connection to Singapore

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.