PT-2026-42190 · Cisco · Nexus 3000 Series Switches+1
Published
2026-05-20
·
Updated
2026-05-23
·
CVE-2026-20171
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 3000 Series Switches versions prior to 10.6(1s)
Cisco Nexus 9000 Series Switches versions prior to 10.6(1s)
Description
A flaw in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode allows an unauthenticated remote attacker to cause a denial of service (DoS) condition. The issue stems from incorrect parsing of a transitive BGP attribute. An attacker can exploit this by sending a crafted BGP update via an established BGP peer session. If the update reaches an affected device, the device may drop the BGP session and flap with the peer forwarding the update, leading to BGP peer flaps.
Recommendations
Update to version 10.6(1s) or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus 3000 Series Switches
Nexus 9000 Series Switches