Cisco has issued a security advisory informing customers of a critical vulnerability in the Intermediate System-to-Intermediate System (IS-IS) functionality of the NX-OS software for Cisco Nexus 3000 and 9000 Series switches . The vulnerability, tracked as CVE-2025-20241 (CVSS 7.4-10), could allow an unauthorized Layer 2-adjacent attacker to send an IS-IS packet, which restarts the IS-IS process, reloading the device and causing a condition denial-of-service (DoS) .

Cisco Nexus 3000 and 9000: Critical security flaw
The vulnerability results from insufficient input validation when parsing incoming IS-IS packets. An attacker must be in the same broadcast domain as the target switch and can exploit the vulnerability by transmitting a specially crafted IS-IS L1 or L2 packet.
See also: New Zip Slip Vulnerability: Exploited When Unzipping Files
Upon receipt, the NX-OS IS-IS daemon may crash and then reload the entire switch, disrupting network routing and traffic forwarding. This condition affects:
– Cisco Nexus 3000 Series Switches
– Cisco Nexus 9000 Series Switches in standalone NX-OS mode
Only devices with IS-IS enabled on at least one interface are vulnerable. Products such as Nexus 9000 in ACI mode, Firepower 1000/2100/4100/9300, MDS 9000, and UCS Fabric Interconnects are not vulnerable.
Cisco's advisory notes that if IS-IS authentication is configured, an attacker must provide valid keys to exploit the vulnerability.

To verify the status of IS-IS, administrators can run the CLI command:

The presence of feature isis, router isis name, and at least one ip router isis name confirms the report. To view live IS-IS peers, use:

Unfortunately, there are no workarounds for the vulnerability in Cisco Nexus 3000 and 9000 Series switches. However, enabling area authentication for IS-IS can mitigate the risk by requiring attackers to authenticate before sending malicious packets.
See also: 28,000+ Citrix instances vulnerable to zero-day vulnerability
Cisco has released free software updates to address the vulnerability. Customers with valid service contracts should download and install the patches from the Cisco Support and Downloads portal.
For those without service contracts, contacting Cisco TAC, with the notification URL and product serial number, will allow access to the necessary fixes.
Cisco Nexus: What the vulnerability means for network security
Cisco's recent notification of a critical vulnerability in the Nexus 3000 and 9000 is not just another security advisory – it's a reminder that network infrastructures, no matter how advanced, remain vulnerable when protection relies solely on perimeter security.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This issue is particularly significant, as Nexus switches form the backbone of many data centers worldwide. An outage at this level not only affects internal connectivity, but can also bring down critical business processes.

It is worth noting that exploiting the vulnerability requires physical proximity to the network. This, on the one hand, limits the scope of the threat; on the other hand, it makes it clear that in environments with shared infrastructure or insider threat scenarios, the consequences can be devastating. It is not difficult to imagine a malicious employee, partner, or even a “guest” server rack in a colocation, gaining access and causing a targeted DoS.
See also: Passkeys: SquareX reveals significant vulnerability
Cisco, as usual, was quick to release patches, but the bigger picture shows something more troubling: routing protocols designed decades ago – such as IS-IS – were not created with today’s threat models in mind. The lack of strong inherent security leaves them constantly exposed to new methods of exploitation.
For organizations, the challenge is not just to “run” the update, but to completely review their strategy around access control in Layer 2 domains, network segmentation, and the use of authentication across all routing protocols. The discussion this vulnerability opens is strategic: how do we ensure that our network backbone itself does not become the point of collapse?
