Vulnslist

find the latest Cisco vulnerabilities

Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability

cisco-sa-n3kn9k_aci_lldp_dos-NdgRrrA3 · High · Published · Updated

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol). Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n3kn9k_aci_lldp_dos-NdgRrrA3 This advisory is part of the February 2026 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: February 2026 Semiannual Cisco FXOS and NX-OS Software Security Advisory Bundled Publication.

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2026-20010
Cisco Bug IDsCSCwq33193, CSCwi75282, CSCwq60777
CVSS ScoreBase 7.4
Base 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Computing System (Managed), Cisco NX-OS Software 10.3(1), Cisco NX-OS Software 10.3(2), Cisco NX-OS Software 10.3(3), Cisco NX-OS Software 10.3(99w), Cisco NX-OS Software 10.3(3w), Cisco NX-OS Software 10.3(99x), Cisco NX-OS Software 10.3(3o), Cisco NX-OS Software 10.3(4a), Cisco NX-OS Software 10.3(3p), Cisco NX-OS Software 10.3(4), Cisco NX-OS Software 10.3(3q), Cisco NX-OS Software 10.3(3x), Cisco NX-OS Software 10.3(4g), Cisco NX-OS Software 10.3(3r), Cisco NX-OS Software 10.3(4h), Cisco NX-OS Software 10.4(1), Cisco NX-OS Software 10.4(2), Cisco NX-OS System Software in ACI Mode 16.0(2h), Cisco NX-OS System Software in ACI Mode 16.0(2j), Cisco NX-OS System Software in ACI Mode 16.0(3d), Cisco NX-OS System Software in ACI Mode 16.0(3e), Cisco NX-OS System Software in ACI Mode 16.0(4c), Cisco NX-OS System Software in ACI Mode 16.0(5h), Cisco NX-OS System Software in ACI Mode 16.0(3g), Cisco NX-OS System Software in ACI Mode 16.0(5j), Cisco NX-OS System Software in ACI Mode 16.0(6c), Cisco NX-OS System Software in ACI Mode 16.0(7e), Cisco NX-OS System Software in ACI Mode 16.0(8e), Cisco NX-OS System Software in ACI Mode 16.0(8f), Cisco NX-OS System Software in ACI Mode 16.0(9c), Cisco NX-OS System Software in ACI Mode 16.0(9d), Cisco NX-OS System Software in ACI Mode 16.0(6h), Cisco NX-OS System Software in ACI Mode 16.0(8h), Cisco NX-OS System Software in ACI Mode 16.1(1f), Cisco NX-OS System Software in ACI Mode 16.1(2f), Cisco NX-OS System Software in ACI Mode 16.1(2g), Cisco NX-OS System Software in ACI Mode 16.1(3f), Cisco NX-OS System Software in ACI Mode 16.1(3g), Cisco NX-OS Software, Cisco NX-OS System Software in ACI Mode, Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Nexus 3000 Series Switches known_affected cisco_csaf CVE-2026-20010 7
Cisco Nexus 9000 Series Switches known_affected cisco_csaf CVE-2026-20010 38
Cisco Unified Computing System (Managed) known_affected cisco_csaf CVE-2026-20010 1

Related Products

Product CVE Evidence
Cisco Firepower Extensible Operating System (FXOS) CVE-2026-20010 Cisco OpenVuln
Cisco NX-OS Software CVE-2026-20010 Cisco OpenVuln
Cisco NX-OS System Software in ACI Mode CVE-2026-20010 Cisco OpenVuln
Cisco Unified Computing System (Managed) CVE-2026-20010 Cisco OpenVuln
Cisco Nexus 9000 Series Switches CVE-2026-20010 Cisco OpenVuln · family-level
Cisco Nexus 3000 Series Switches CVE-2026-20010 Cisco OpenVuln · family-level