Database/Firmware, BMC & network fabric
Cisco NX-OS (eBGP implementation): An unauthenticated remote attacker can wedge the switch through the eBGP
Impact
An unauthenticated remote attacker can wedge the switch through the eBGP implementation. In a BGP-underlay leaf/spine — the standard GPU-cluster design — the routing daemon going down means the rack loses reachability, and a coordinated attack against several leaves partitions the fabric mid-training-run.
Who can reach it
Unauthenticated, remote to the BGP process. Requires the ability to reach the switch's BGP listener.
What to do
NX-OS upgrade plus reload. Harden with strict neighbor ACLs and CoPP in the meantime — live config. Because this affects the underlay control plane, schedule the reload per MLAG/ECMP pair so the fabric never loses both paths.
References
Related entries
- Cisco NX-OS (DHCPv6 relay agent): A crafted DHCPv6 packet takes the switch out. Relevant because DHCP relay is normallyCVE-2024-20446 · Cisco NX-OS (DHCPv6 relay agent)High
- Linux bnxt_en driver (TX BD bd_cnt field masking): The 5-bit bd_cnt field in the transmit buffer descriptorCVE-2025-22108 · Linux bnxt_en driver (TX BD bd_cnt field masking)High
- Intel AMT and Intel Standard Manageability firmware (current CSME generations): Out-of-bounds write in AMT/ISM firmwareCVE-2025-32008 · Intel AMT and Intel Standard Manageability firmware (current CSME generations)High
- Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loadsCVE-2025-59887 · Eaton UPS Companion (EUC) software installerHigh
- Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): Unauthenticated authentication bypass givesCVE-2026-22620 · Eaton Tripp Lite series PADM firmware (rack PDU / ATS management)High
- Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configuredCVE-2026-73454 · Arista EOS gNSI Credentialz serviceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.