Tuesday, March 4, 2025
HomeCiscoCisco Nexus 3000 and 9000 Series Switches Flaw Let Attackers Trigger DoS...

Cisco Nexus 3000 and 9000 Series Switches Flaw Let Attackers Trigger DoS Attack

Published on

SIEM as a Service

Follow Us on Google News

A Denial-of-Service vulnerability has been discovered in the Cisco Nexus 3000 and 9000 series switches, which could allow a threat actor to cause a denial-of-service condition due to a flaw in the IS-IS (Intermediate System-to-Intermediate System) protocol.

ISIS is one of the family of IP routing protocols and can also act as an Interior Gateway Protocol (IGP), which is used to distribute IP routing information throughout a very large network that has a single routing policy.

The vulnerability exists due to the unexpected restart of the IS-IS process, causing an infected device to restart. Threat actors can exploit this vulnerability by sending a crafted IS-IS packet to an infected device that can cause the device to reload.

CVE-2023-20169: Cisco Nexus 3000 and 9000 Series Switches IS-IS Protocol Denial of Service Vulnerability

Additionally, there is insufficient input validation when parsing ingress IS-IS packets, leading to this denial of service condition on the affected devices. This vulnerability has been assigned with a CVE ID of CVE-2023-20169 and has a severity of 7.4 (High), as stated by NVD. 

However, there are prerequisites for threat actors to exploit this vulnerability. The threat actor must be layer 2 adjacent to the affected device for successful exploitation. 

Cisco has released a security advisory for this vulnerability, including a list of affected devices and a list of not vulnerable devices.

Affected Products & How to Detect

As mentioned by Cisco, the affected products include Nexus 3000 Series Switches and Nexus 9000 Series Switches in standalone NX-OS mode. In addition, Cisco has also provided steps to detect if a Switch has enabled IS-IS Protocol. 

“A device that is configured for IS-IS authentication can still be affected by this vulnerability. For more information, see Cisco Nexus 9000 Series NX-OS Unicast Routing Configuration Guide, Release 10.3(x): IS-IS Authentication,” reads the security advisory released by Cisco.

The list of products that Cisco has confirmed are not vulnerable can be checked in this Cisco security advisory section.

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...