Database/Firmware, BMC & network fabric
Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is a
Impact
A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is a VTEP, so an attacker with a foothold in any tenant overlay can knock out leaves one at a time and stall collectives cluster-wide. Reachable from inside a tenant's own overlay, which is what makes it interesting — it does not need underlay access.
Who can reach it
Unauthenticated, remote — the attacker needs to be able to land a crafted VXLAN packet on the switch's VTEP address. In practice that means a compromised workload or a tenant that can source arbitrary UDP.
What to do
NX-OS upgrade plus reload. If NGOAM is not in use, disabling the feature is a live config change with no reload and removes the exposure entirely — do that first, patch on the next window.
References
Related entries
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): Improper input validation in the *manageability*CVE-2021-33141 · Intel Ethernet Adapter manageability firmware (NC-SI / sideband path)High
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontCVE-2022-2601 · GRUB2 (font engine, grub_font_construct_glyph)High
- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseCVE-2022-36392 · Intel AMT / Standard Manageability firmwareHigh
- GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of boundsCVE-2022-3775 · GRUB2 (font engine, blit_comb)High
- Cisco NX-OS (MPLS traffic handling / netstack): Crafted MPLS traffic restarts netstack, which stops the switchCVE-2024-20267 · Cisco NX-OS (MPLS traffic handling / netstack)High
- Cisco NX-OS (eBGP implementation): An unauthenticated remote attacker can wedge the switch through the eBGPCVE-2024-20321 · Cisco NX-OS (eBGP implementation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.