CVE-2025-20111

Cisco Nexus 3000 and 9000 Series Switches Layer 2 Ethernet Denial of Service Vulnerability

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
23.9th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 26, 2025
Assigned by cisco

Description

A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload.

Weakness: CWE-1220

Affected products

Vendor Product Category Matched by
Cisco Cisco NX-OS Software Routing & Switching cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco NX-OS Software