Database/Firmware, BMC & network fabric
Cisco NX-OS: out-of-bounds read lets an unauthenticated attacker crash the switch
Impact
An unauthenticated attacker triggers an out-of-bounds read that produces an availability-only impact with a scope change (CVSS 8.6, S:C, A:H) - the crash affects more than the component containing the bug. In a GPU datacenter the cost is measured in lost job time: a leaf or spine reload drops the collectives that distributed training depends on, and jobs fail rather than slow down. Despite the CWE, Cisco scores no confidentiality impact, so this reads as a crash rather than a memory-disclosure primitive. Mechanism and affected interface are not published.
Who can reach it
Anyone with network reach to an affected NX-OS device; no authentication, no user interaction. Cisco does not say which service parses the attacker-controlled input.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch - move traffic to the redundant peer first. Limiting network reach to the device's management plane reduces, but does not establish the bounds of, exposure.
References
Related entries
- Cisco NX-OS: mishandled exceptional conditions let an unauthenticated attacker deny serviceCVE-2026-76458 · Cisco NX-OS Software (improper handling of exceptional conditions, also ACI mode and UCS Managed)High
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
- Intel Ethernet Adapter manageability firmware (access control): Improper access control in Intel Ethernet adapterCVE-2021-33162 · Intel Ethernet Adapter manageability firmware (access control)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.