Database/Firmware, BMC & network fabric
Cisco NX-OS: improper access control lets an unauthenticated attacker fully compromise the switch
Impact
An unauthenticated attacker with network reach to an NX-OS device gets full confidentiality, integrity and availability impact on the switch itself (CVSS 9.8, AV:N/PR:N/UI:N). On a GPU fleet the Nexus/ACI layer is the leaf-spine and often the storage and out-of-band path, so control of a switch means control of what crosses between tenants: VLAN and VRF boundaries, port mirroring, and the routes that carry NFS or object storage traffic. Cisco found this internally in a hardening review and published no mechanism, so there is no way to scope it more narrowly than "reachable on the management or data plane". The same bulletin covers Cisco UCS Managed, which is the server-side management path for the same racks.
Who can reach it
Anyone with network reach to an affected NX-OS device - no authentication and no user interaction. In practice that is anyone on the management VLAN, plus anyone on a data-plane segment the device terminates. Cisco does not say which interface or service is affected.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin (cisco-sa-hardening-nxosw1-cWzSbtR); Cisco publishes no workaround for this class. An NX-OS upgrade reloads the switch, so for a leaf pair this is a maintenance window per switch with traffic drained to the peer, and for a single-homed segment it is an outage. Until the upgrade, keep NX-OS management interfaces off any tenant-reachable network and restrict them to a jump path.
References
Related entries
- Cisco NX-OS: crafted MPLS echo-request gives unauthenticated root code execution on Nexus switchesCVE-2026-76465 · Cisco NX-OS MPLS OAM (echo-request handling) on Nexus 3000/9000 switchesCritical
- Cisco NX-OS: crafted HTTP request to NX-API yields unauthenticated root code executionCVE-2026-76471 · Cisco NX-OS NX-API (HTTP request input validation)Critical
- Cisco NX-OS: crafted IP packets to a VXLAN OAM interface give unauthenticated root code executionCVE-2026-76485 · Cisco NX-OS NGOAM (VXLAN OAM packet handling)Critical
- Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code executionCVE-2026-76501 · Cisco NX-OS NGOAM (SRv6 OAM packet handling)Critical
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.