Cisco informed its customers on Wednesday that it had patched command injection and denial of service (DoS) vulnerabilities in some of its Nexus Switches.
See also: Chinese hackers breach telecommunications via Cisco routers

One of the vulnerabilities, known as CVE-2025-20111, is considered a high-risk issue related to the incorrect handling of certain Ethernet. This vulnerability affects the health monitoring diagnostic tool for Nexus 3000 and 9000 — specifically, on the 9000 series, the vulnerability only affects NX-OS operation in standalone mode.
This vulnerability can allow an attacker, without authentication, to exploit your device and cause a Denial of Service (DoS) condition.
Another important advisory concerns a medium severity vulnerability affecting Nexus 3000 and 9000 series switches. This vulnerability can be exploited by a local attacker with administrator credentials.
See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks
On Wednesday, Cisco published an advisory regarding four medium severity bugs in its Application Policy Infrastructure Controller (APIC), providing information on how to address these issues.

The security vulnerabilities can be used for XSS attacks, DoS attacks, arbitrary command execution, and access to sensitive information. However, the attacker would need administrator credentials. The company has acknowledged members of the NATO Cybersecurity Center for reporting these vulnerabilities.
Cisco states that, to date, none of these vulnerabilities in Nexus Switches have been used in attacks. However, it is common for malicious users to exploit flaws in Cisco products in their attacks.
CISA's Known Vulnerabilities (KEV) list includes approximately 70 Cisco vulnerabilitiesthat have been targeted by malicious actors in attacks over the past ten years.
See also: Cisco confirms second data leak
DoS attacks , also known as Denial of Service attacks, are one of the most common forms of online threats you may encounter. In these attacks, the hacker floods a server or network with excessive requests, seeking to exhaust its resources and make it unavailable to users. DoS attacks can target websites, email servers, and even online games, causing financial damage and reputational damage. Using a strong firewall architecture and advanced traffic filtering techniques can help prevent such attacks.
Source: securityweek
