GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco Nexus 9000 ACI mode: DHCP-port packets bypass EPG contracts between endpoint groups

CVSS 5.8CVE-2026-20038Firmware, BMC & network fabriccurated

Impact

EPG contracts are the segmentation boundary in an ACI fabric - on a multi-tenant GPU estate they are often what keeps one tenant's compute, storage and management segments from reaching another's. An unauthenticated attacker who can get IPv4 or IPv6 traffic through the switch with UDP source and destination ports matching DHCP can send packets across EPGs that the contract policy was supposed to drop. Scope is changed per the vendor vector: the policy violation affects endpoints beyond the switch itself. The record describes an integrity/segmentation-bypass impact only - no confidentiality loss and no code execution on the switch - and the bypass is constrained to the DHCP port pair.

Who can reach it

Anyone able to inject crafted UDP packets into a fabric path that traverses an affected Nexus 9000 in ACI mode, for example a tenant workload on an attached leaf port. No authentication to the switch is required.

What to do

Apply the fixed NX-OS ACI release listed in Cisco advisory cisco-sa-aci-epgcbp-SfDU7NLf. Upgrading an ACI leaf or spine means a device reload, so it has to be staged across the fabric with redundancy in mind - on a GPU cluster that also means planning around RoCE/IP storage paths that run through the same leaves. The advisory is the authority on fixed versions and on whether any interim filtering is supported; the record here does not state a workaround.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.