HomeSecurityCisco fixes vulnerabilities in Nexus Switches

Cisco patches vulnerabilities in Nexus Switches

Cisco informed its customers on Wednesday that it had patched command injection and denial of service (DoS) vulnerabilities in some of its Nexus Switches.

See also: Chinese hackers breach telecommunications via Cisco routers

Nexus Switches vulnerabilities

One of the vulnerabilities, known as CVE-2025-20111, is considered a high-risk issue related to the incorrect handling of certain Ethernet. This vulnerability affects the health monitoring diagnostic tool for Nexus 3000 and 9000 — specifically, on the 9000 series, the vulnerability only affects NX-OS operation in standalone mode.

This vulnerability can allow an attacker, without authentication, to exploit your device and cause a Denial of Service (DoS) condition.

Another important advisory concerns a medium severity vulnerability affecting Nexus 3000 and 9000 series switches. This vulnerability can be exploited by a local attacker with administrator credentials.

See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

On Wednesday, Cisco published an advisory regarding four medium severity bugs in its Application Policy Infrastructure Controller (APIC), providing information on how to address these issues.

Cisco patches vulnerabilities in Nexus Switches

The security vulnerabilities can be used for XSS attacks, DoS attacks, arbitrary command execution, and access to sensitive information. However, the attacker would need administrator credentials. The company has acknowledged members of the NATO Cybersecurity Center for reporting these vulnerabilities. 

Cisco states that, to date, none of these vulnerabilities in Nexus Switches have been used in attacks. However, it is common for malicious users to exploit flaws in Cisco products in their attacks.

CISA's Known Vulnerabilities (KEV) list includes approximately 70 Cisco vulnerabilitiesthat have been targeted by malicious actors in attacks over the past ten years.

See also: Cisco confirms second data leak

DoS attacks , also known as Denial of Service attacks, are one of the most common forms of online threats you may encounter. In these attacks, the hacker floods a server or network with excessive requests, seeking to exhaust its resources and make it unavailable to users. DoS attacks can target websites, email servers, and even online games, causing financial damage and reputational damage. Using a strong firewall architecture and advanced traffic filtering techniques can help prevent such attacks.

Source: securityweek

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS