Database/Firmware, BMC & network fabric
Cisco Nexus 9000 ACI mode: DHCP-port packets bypass EPG contracts between endpoint groups
Impact
EPG contracts are the segmentation boundary in an ACI fabric - on a multi-tenant GPU estate they are often what keeps one tenant's compute, storage and management segments from reaching another's. An unauthenticated attacker who can get IPv4 or IPv6 traffic through the switch with UDP source and destination ports matching DHCP can send packets across EPGs that the contract policy was supposed to drop. Scope is changed per the vendor vector: the policy violation affects endpoints beyond the switch itself. The record describes an integrity/segmentation-bypass impact only - no confidentiality loss and no code execution on the switch - and the bypass is constrained to the DHCP port pair.
Who can reach it
Anyone able to inject crafted UDP packets into a fabric path that traverses an affected Nexus 9000 in ACI mode, for example a tenant workload on an attached leaf port. No authentication to the switch is required.
What to do
Apply the fixed NX-OS ACI release listed in Cisco advisory cisco-sa-aci-epgcbp-SfDU7NLf. Upgrading an ACI leaf or spine means a device reload, so it has to be staged across the fabric with redundancy in mind - on a GPU cluster that also means planning around RoCE/IP storage paths that run through the same leaves. The advisory is the authority on fixed versions and on whether any interim filtering is supported; the record here does not state a workaround.
References
Related entries
- Cisco NX-OS: missing rate limiting on some protocols lets flooded data-plane traffic destabilize control planeCVE-2026-20173 · Cisco NX-OS Software (data plane rate limiting for UDP/TCP connections)Medium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
- AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soCVE-2023-34472 · AMI MegaRAC SPx (BMC web interface, HTTP header handling)Medium
- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPCVE-2024-21981 · AMD Secure Processor - cryptographic key usage controlMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.