GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDP

CVSS 6.6CVE-2024-20294Firmware, BMC & network fabriccurated

Impact

An unauthenticated adjacent attacker sends crafted LLDP frames and takes the switch down, with scope change. Any compromised host NIC plugged into the fabric can do this.

Who can reach it

Layer-2 adjacency - i.e. anything connected to the switch.

What to do

Upgrade NX-OS/FXOS per cisco-sa-nxos-lldp-dos-z7PncTgt. Switch reboot required. Interim: disable LLDP on host-facing ports where you do not depend on it for topology discovery.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.