GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: unvalidated command input lets an unauthenticated attacker deny service beyond the device

CVSS 8.6CVE-2026-76456Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker causes an availability-only impact with a scope change (CVSS 8.6, PR:N, S:C, A:H) - the failure reaches past the vulnerable component into other parts of the system. For a datacenter switch that means a control-plane or process crash whose blast radius is the traffic the device carries, not just one daemon. On a GPU cluster, a leaf or spine dropping takes collective communication with it: in-flight distributed training jobs fail rather than degrade, and a storage path crossing that switch stalls every node behind it. Cisco found this internally and published no mechanism or affected interface.

Who can reach it

Anyone with network reach to an affected NX-OS device - no credentials, no user interaction. Cisco does not identify which service or command path accepts the input, so assume both management and data-plane exposure until it does.

What to do

Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch, so schedule it per device with traffic on the peer. Keep NX-OS management interfaces off tenant-reachable networks in the meantime - this is availability-only, so the practical interim control is reducing who can send the device traffic at all.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.