Database/Firmware, BMC & network fabric
Cisco NX-OS: out-of-bounds write lets an authenticated user take over the switch
Impact
An authenticated low-privilege user triggers a memory-corrupting out-of-bounds write that yields full confidentiality, integrity and availability impact on the device (CVSS 8.8). Memory corruption in a switch process is both an escalation path and a reliable way to crash the control plane, so on a GPU cluster the realistic outcomes are control of a leaf that carries multiple tenants and an unplanned reconvergence that stalls distributed training jobs mid-run. Cisco discovered it internally and did not say which process or input path is affected.
Who can reach it
Any user with valid low-privilege credentials on an affected NX-OS device, reachable over the network. Authentication required, no user interaction.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch - drain to the redundant peer first. Restricting who holds switch login credentials limits exposure but does not remove it.
References
Related entries
- IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesCVE-2026-7868 · IBM OpenBMC (Power S1122/S1124 service processor firmware, ReadOnly role)High
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-006-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-012-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedNCVD-2022-001-infiniband-roce-local-rnic-kerne · InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processesHigh
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsCVE-2023-20514 · AMD Secure Processor - TEE parameter handlingHigh
- UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTCVE-2025-20105 · UEFI firmware SMM modules in Intel reference platform firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.