🔒Cisco Patches Critical IOS XR Bugs, Mitigates Nexus Flaws
Critical Nexus Flaws Require Immediate Action
TL;DR
Cisco has released updates to fix critical vulnerabilities in IOS XR and mitigations for Nexus 9000 Series Switches. The most severe flaw scores 9.8 on the CVSS scale and allows unauthenticated attackers to execute code with root privileges.
Cisco has released updates to fix critical vulnerabilities in its IOS XR operating system and provided mitigations for a make-me-root flaw in the Nexus 9000 Series Switches. The most severe flaw scores 9.8 on the CVSS scale and allows unauthenticated attackers to execute code with root privileges. This affects network devices running IOS XR and Nexus 9000 Series Switches. Ten Nexus 9000 devices are affected, and Cisco recommends using infrastructure access control lists (iACLs) to mitigate the vulnerability. The company has not yet created a software update to fix the flaw permanently.

Key Points
Cisco released updates to fix critical vulnerabilities in IOS XR, scoring 9.8 on the CVSS scale.
A make-me-root flaw in Nexus 9000 Series Switches allows unauthenticated attackers to execute code with root privileges.
The vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) VRF.
Cisco recommends mitigating the vulnerability by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic.
Ten Nexus 9000 devices are affected, and Cisco has delivered a download to help implement the mitigation.
Why It Matters
If you're running network devices with IOS XR or Nexus 9000 Series Switches, this update is crucial. The most severe flaw scores 9.8 on the CVSS scale and allows unauthenticated attackers to execute code with root privileges. Network administrators should immediately apply the updates and implement the recommended mitigations to protect their infrastructure.
Frequently Asked Questions
Why does this matter?
If you're running network devices with IOS XR or Nexus 9000 Series Switches, this update is crucial. The most severe flaw scores 9.8 on the CVSS scale and allows unauthenticated attackers to execute code with root privileges. Network administrators should immediately apply the updates and implement the recommended mitigations to protect their infrastructure.
What happened?
Cisco has released updates to fix critical vulnerabilities in IOS XR and mitigations for Nexus 9000 Series Switches. The most severe flaw scores 9.8 on the CVSS scale and allows unauthenticated attackers to execute code with root privileges.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,463 builders reading daily.