what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Cisco Security Advisory 20121107-n1k

Cisco Security Advisory 20121107-n1k
Posted Nov 8, 2012
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - The Cisco Product Security Incident Response Team (PSIRT) would like to notify customers of an issue that may impact their network security posture when upgrading the Cisco Nexus 1000V Series Switches to Software Release 4.2(1)SV1(5.2) with deployments that have Cisco Virtual Security Gateway (VSG) integration. This issue will manifest itself when administrators perform an in-service software upgrade to Software Release 4.2(1)SV1(5.2) from Software Release 4.2(1)SV1(5.1a) or earlier. After the software upgrade, a bug in Software Release 4.2(1)SV1(5.2) could cause all the virtual Ethernet ports on the Virtual Ethernet Modules (VEM) of the Cisco Nexus 1000V Series Switch to stay in No-Policy pass-through mode because a valid VSG license is not actively installed. As a result, the VEMs no longer use a configured Cisco VSG; therefore, the virtual machines (VM) are not firewalled and traffic is not inspected by the VSG.

tags | advisory
systems | cisco
SHA-256 | e173bf86ec7f8fa6a6b464720bcc4ee2a42d6116b5425370d71bcba2ab7c0932

Cisco Security Advisory 20121107-n1k

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Cisco Nexus 1000V Series Switch Software Release 4.2(1)SV1(5.2)
Virtual Security Gateway Bypass Issue

Document ID: cisco-sr-20121107-n1k

Revision 1.0

For Public Release 2012 November 7 16:00 UTC (GMT)
- ----------------------------------------------------------------------

Cisco Response
==============

The Cisco Product Security Incident Response Team (PSIRT) would like
to notify customers of an issue that may impact their network security
posture when upgrading the Cisco Nexus 1000V Series Switches to
Software Release 4.2(1)SV1(5.2) with deployments that have Cisco
Virtual Security Gateway (VSG) integration. This issue will manifest
itself when administrators perform an in-service software upgrade to
Software Release 4.2(1)SV1(5.2) from Software Release 4.2(1)SV1(5.1a)
or earlier.

After the software upgrade, a bug in Software Release 4.2(1)SV1(5.2)
could cause all the virtual Ethernet ports on the Virtual Ethernet
Modules (VEM) of the Cisco Nexus 1000V Series Switch to stay in
No-Policy pass-through mode because a valid VSG license is not
actively installed. As a result, the VEMs no longer use a configured
Cisco VSG; therefore, the virtual machines (VM) are not firewalled and
traffic is not inspected by the VSG.

This software bug is documented in Cisco Bug ID CSCud01427 and a
software bulletin for Software Release 4.2(1)SV1(5.2) is in the
process of being published. Additional Information

This response is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20121107-n1k
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools - http://gpgtools.org

iF4EAREIAAYFAlCahB0ACgkQUddfH3/BbTocEgD/ZAzdVLQZCcaLo41tATesEH9J
0O/Ijdnc8Fw7B3pBgrgBAI/6M8mWC/CJWGF6b6OkDhxu8aiNUUmZX645hWms9h8c
=MMfv
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close