GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: missing rate limiting on some protocols lets flooded data-plane traffic destabilize control plane

CVSS 5.8CVE-2026-20173Firmware, BMC & network fabriccurated

Impact

Rate limiting is not applied to some protocols, so a high rate of UDP or TCP connections aimed at a data-plane interface starves switch resources and leaks into the control plane. The observed effect is packet loss and temporary disruption of routing and control-plane protocols - on a datacenter switch that means adjacency flaps, which on a GPU fabric can stall collective operations and abort long training jobs well out of proportion to the switch's own downtime. The condition clears by itself once the traffic stops, and there is no code execution or data disclosure.

Who can reach it

Any unauthenticated party that can send high-rate traffic to a data-plane interface on an affected switch - in practice a tenant workload or a compromised host on an attached segment, not necessarily anyone with management access.

What to do

Upgrade to a fixed NX-OS release per Cisco advisory cisco-sa-nxos-nscpdos-SnderkC7; an NX-OS upgrade reloads the device, so schedule it per switch against fabric redundancy. Until then, the usual control-plane protection levers (CoPP tuning, ingress policing on tenant-facing ports) limit exposure, but the record does not name a vendor-sanctioned workaround - treat the advisory as authoritative.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.