GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: mishandled exceptional conditions let an unauthenticated attacker deny service

CVSS 8.6CVE-2026-76458Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker drives the device into an error path it handles badly, causing an availability-only impact with a scope change (CVSS 8.6, S:C, A:H). This is the classic malformed-input switch crash: cheap to trigger repeatedly, which makes it worse than a one-off reload because the device can be held down. On a GPU fleet a flapping leaf is harder to work around than a dead one - jobs fail, rejoin, and fail again, and the fabric reconverges each time. Cisco found this in an internal review and published no mechanism.

Who can reach it

Anyone with network reach to an affected NX-OS device; no credentials, no user interaction. The affected protocol or service is not disclosed.

What to do

Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch, so plan per-device windows with traffic drained to the peer. Until then, restrict which networks can reach the device's control plane.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.