Database/Firmware, BMC & network fabric
Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDP
CVSS 6.6CVE-2024-20294Firmware, BMC & network fabriccurated
Impact
An unauthenticated adjacent attacker sends crafted LLDP frames and takes the switch down, with scope change. Any compromised host NIC plugged into the fabric can do this.
Who can reach it
Layer-2 adjacency - i.e. anything connected to the switch.
What to do
Upgrade NX-OS/FXOS per cisco-sa-nxos-lldp-dos-z7PncTgt. Switch reboot required. Interim: disable LLDP on host-facing ports where you do not depend on it for topology discovery.
References
Related entries
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+CVE-2025-0038 · AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmwareMedium
- TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingCVE-2025-2884 · TCG TPM 2.0 reference implementation (CryptHmacSign)Medium
- Linux kernel (drivers/infiniband/hw/irdma): A stale flag caused the CQ memory-registration path to read one elementCVE-2026-74346 · Linux kernel (drivers/infiniband/hw/irdma)Medium
- Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler race: A race in theCVE-2011-0695 · Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler raceMedium
- ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port files: The RDMACVE-2012-4518 · ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port filesMedium
- Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE): Pre-authentication remoteCVE-2014-2739 · Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.