Vulnerable Products:
This vulnerability affects Cisco products if they are running a vulnerable release of the following Cisco Software and have SISF enabled:
IOS Software (CSCwk04230 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk04230"]) IOS XE Software (CSCvq14413 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq14413"]) IOS XE Software for WLCs (CSCvo13585 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo13585"])1 WLC AireOS Software (CSCwj88828 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj88828"])
This vulnerability also affects the following Cisco products if they are running a vulnerable release of Cisco NX-OS Software and have SISF enabled:
Nexus 3000 Series Switches (CSCwk02672 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk02672"]) Nexus 7000 Series Switches (CSCwk02785 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk02785"]) Nexus 9000 Series Switches in standalone NX-OS mode (CSCwk02672 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk02672"])
For information about which Cisco software releases are vulnerable, see the Fixed Software ["#fs"] section of this advisory. Determine the Device Configuration Cisco IOS and IOS XE Software
In Cisco IOS Software and Cisco IOS XE Software, SISF is not enabled by default. To determine whether a device has SISF enabled, use the show device-tracking policies or show ipv6 snooping policies CLI command (it may vary depending on the software release). If there are any policies listed in the output, SISF is enabled. The following examples show samples of the output when these commands are issued on an affected device:
switch# show device-tracking policies Target Type Policy Feature Target range vlan...
12.2(6)I115.1(3)SVR115.1(3)SVR1015.1(3)SVR215.1(3)SVR315.1(3)SVS15.1(3)SVS115.1(3)SVT115.1(3)SVT215.1(3)SVT3+69 more16.10.116.10.1a16.10.1b16.10.1c16.10.1d16.10.1e16.10.1f16.10.1g16.10.1s16.10.2+101 more10.1(1)10.1(2)10.1(2t)10.2(1)10.2(2)10.2(3)10.2(3t)10.2(3v)10.2(4)10.2(5)+50 more7.3(0)D1(1)7.3(0)DX(1)7.3(1)D1(1)7.3(2)D1(1)7.3(2)D1(1d)7.3(2)D1(2)7.3(2)D1(3)7.3(2)D1(3a)7.3(3)D1(1)7.3(4)D1(1)+33 more10.1(1)10.1(2)10.2(1)10.2(1q)10.2(2)10.2(2a)10.2(3)10.2(4)10.2(5)10.2(6)+59 moreExploitability
AV:AAC:LPR:NUI:NScope
S:CImpact
C:NI:NA:H7.4/CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H