Database/Firmware, BMC & network fabric
Cisco NX-OS: mishandled exceptional conditions let an unauthenticated attacker deny service
Impact
An unauthenticated attacker drives the device into an error path it handles badly, causing an availability-only impact with a scope change (CVSS 8.6, S:C, A:H). This is the classic malformed-input switch crash: cheap to trigger repeatedly, which makes it worse than a one-off reload because the device can be held down. On a GPU fleet a flapping leaf is harder to work around than a dead one - jobs fail, rejoin, and fail again, and the fabric reconverges each time. Cisco found this in an internal review and published no mechanism.
Who can reach it
Anyone with network reach to an affected NX-OS device; no credentials, no user interaction. The affected protocol or service is not disclosed.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch, so plan per-device windows with traffic drained to the peer. Until then, restrict which networks can reach the device's control plane.
References
Related entries
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
- Intel Ethernet Adapter manageability firmware (access control): Improper access control in Intel Ethernet adapterCVE-2021-33162 · Intel Ethernet Adapter manageability firmware (access control)High
- Crypto API Toolkit for Intel SGX: Improper access control in the SGX Crypto API Toolkit lets an authenticated userCVE-2022-21163 · Crypto API Toolkit for Intel SGXHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.