Cisco NX-OS (unspecified versions) - Insufficient Granularity of Access Control (CVE-2025-20111)

Description

A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device.

A successful exploit could allow the attacker to cause the device to reload.

Remediation

Update to the latest version.

Risk

Impact
High
Probability
High
CVSS v4 Score
CVSS v3 Score
7.4 / 10
CVSS v2 Score
6.1 / 10
EPSS
0.1 %

Information

Category
Broken Access Control
CWE
  • CWE-1220
Known Exploitation Activity
No exploitations reported

OWASP

OWASP 2013
A7 - Missing Function Level Access Control
OWASP 2017
A5 - Broken Access Control
OWASP 2021
A1 - Broken Access Control