Cisco released a security advisory that alerted its customers of a high-severity vulnerability (CVE-2023-20185) in its Nexus 9000 fabric series switches this week. The flaw could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic and for now, the vendor has not released any software updates to address this vulnerability and no workarounds have been suggested.

Found during Cisco’s internal security testing, the bug is in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in application-centric infrastructure (ACI) mode, which is typically deployed in data centers for controlling physical and virtual networks.

The networking giant noted this vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode that are running releases 14.0 and later if they are part of a Multi-Site topology and have the CloudSec encryption feature enabled. Notably, Cisco Nexus 9000 Series Switches in standalone NX-OS mode are not affected by this flaw.

“This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches,” Cisco noted. “An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption.”

No exploit or patch for now

A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites, posing a threat to data confidentiality and integrity.

As of now, the Cisco Product Security Incident Response Team has not found any public announcements or malicious use of the vulnerability.

And in the advisory, Cisco has not released software updates to address the vulnerability. The company has advised its customers to disable the ACI Multi-Site CloudSec encryption feature for the Cisco Nexus 9332C and Nexus 9364C Switches and the Cisco Nexus N9K-X9736C-FX Line Card and reach out to their support organization to evaluate alternative options.

Security experts express concerns over Cisco’s new vulnerability

Several security experts have expressed their concerns about this new vulnerability and the lack of software updates from Cisco to address it.

“I’m not sure I’ve ever seen a vendor says there are no updates and that they should unplug the device and find another product instead,” John Bambenek, principal threat hunter at Netenrich, said in a statement. “Being able to intercept and decrypt (and potentially modify traffic) is a significant issue, especially in data centers where sensitive data is stored and accessed.”

Callie Guenther, cyber threat research senior manager at Critical Start, echoed the vulnerability's complexities, noting the vulnerability is yet to be officially listed by databases like MITRE and the National Institute of Standards and Technology (NIST). “While the absence of patches and official listings may raise concerns, it is important to understand that addressing vulnerabilities of this nature involves complex processes, coordination, and testing. ”

Guenther urges impacted users to follow Cisco's guidance and disable the affected switches as a precautionary measure, even if this may cause operational disruptions and impact network functionality.