GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: out-of-bounds read lets an unauthenticated attacker crash the switch

CVSS 8.6CVE-2026-76457Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker triggers an out-of-bounds read that produces an availability-only impact with a scope change (CVSS 8.6, S:C, A:H) - the crash affects more than the component containing the bug. In a GPU datacenter the cost is measured in lost job time: a leaf or spine reload drops the collectives that distributed training depends on, and jobs fail rather than slow down. Despite the CWE, Cisco scores no confidentiality impact, so this reads as a crash rather than a memory-disclosure primitive. Mechanism and affected interface are not published.

Who can reach it

Anyone with network reach to an affected NX-OS device; no authentication, no user interaction. Cisco does not say which service parses the attacker-controlled input.

What to do

Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch - move traffic to the redundant peer first. Limiting network reach to the device's management plane reduces, but does not establish the bounds of, exposure.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.