Database/Firmware, BMC & network fabric
Cisco NX-OS: missing rate limiting on some protocols lets flooded data-plane traffic destabilize control plane
Impact
Rate limiting is not applied to some protocols, so a high rate of UDP or TCP connections aimed at a data-plane interface starves switch resources and leaks into the control plane. The observed effect is packet loss and temporary disruption of routing and control-plane protocols - on a datacenter switch that means adjacency flaps, which on a GPU fabric can stall collective operations and abort long training jobs well out of proportion to the switch's own downtime. The condition clears by itself once the traffic stops, and there is no code execution or data disclosure.
Who can reach it
Any unauthenticated party that can send high-rate traffic to a data-plane interface on an affected switch - in practice a tenant workload or a compromised host on an attached segment, not necessarily anyone with management access.
What to do
Upgrade to a fixed NX-OS release per Cisco advisory cisco-sa-nxos-nscpdos-SnderkC7; an NX-OS upgrade reloads the device, so schedule it per switch against fabric redundancy. Until then, the usual control-plane protection levers (CoPP tuning, ingress policing on tenant-facing ports) limit exposure, but the record does not name a vendor-sanctioned workaround - treat the advisory as authoritative.
References
Related entries
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathCVE-2021-3696 · GRUB2 (PNG grayscale reader)Medium
- AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soCVE-2023-34472 · AMI MegaRAC SPx (BMC web interface, HTTP header handling)Medium
- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPCVE-2024-21981 · AMD Secure Processor - cryptographic key usage controlMedium
- Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain dataCVE-2025-31356 · Intel TDX (hypervisor-facing ring 0 interface)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.