PT-2025-34888 · Cisco · Cisco Nexus 3000 Series Switches+2
Published
2025-08-27
·
Updated
2025-08-27
·
CVE-2025-20262
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches
Description:
A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition. This issue is due to improper processing of PIM6 ephemeral data queries. An attacker could exploit this by sending a crafted ephemeral query to an affected device through the following methods:
NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. A successful exploit could cause the PIM6 process to crash and restart, potentially causing adjacency flaps and resulting in a DoS of the PIM6 and ephemeral query processes.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nexus
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches