Database/Firmware, BMC & network fabric
Cisco NX-OS: unvalidated command input lets an unauthenticated attacker deny service beyond the device
Impact
An unauthenticated attacker causes an availability-only impact with a scope change (CVSS 8.6, PR:N, S:C, A:H) - the failure reaches past the vulnerable component into other parts of the system. For a datacenter switch that means a control-plane or process crash whose blast radius is the traffic the device carries, not just one daemon. On a GPU cluster, a leaf or spine dropping takes collective communication with it: in-flight distributed training jobs fail rather than degrade, and a storage path crossing that switch stalls every node behind it. Cisco found this internally and published no mechanism or affected interface.
Who can reach it
Anyone with network reach to an affected NX-OS device - no credentials, no user interaction. Cisco does not identify which service or command path accepts the input, so assume both management and data-plane exposure until it does.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch, so schedule it per device with traffic on the peer. Keep NX-OS management interfaces off tenant-reachable networks in the meantime - this is availability-only, so the practical interim control is reducing who can send the device traffic at all.
References
Related entries
- Cisco NX-OS: out-of-bounds read lets an unauthenticated attacker crash the switchCVE-2026-76457 · Cisco NX-OS Software (out-of-bounds read, also ACI mode and UCS Managed)High
- Cisco NX-OS: mishandled exceptional conditions let an unauthenticated attacker deny serviceCVE-2026-76458 · Cisco NX-OS Software (improper handling of exceptional conditions, also ACI mode and UCS Managed)High
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.