Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2834 articles · 164367 vulns · 36/41 feeds (7d)
← Back to list
6.8
CVE-2026-20171
Cisco · Cisco NX-OS Software

Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability

Description

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition.

Affected Products

VendorProductVersions
CiscoCisco NX-OS Software10.2(1), 10.2(1q), 10.2(2), 10.2(3), 10.2(3t), 10.2(2a), 10.3(1), 10.2(4), 10.3(2), 10.3(3), 10.2(5), 10.2(3v), 10.4(1), 10.3(99w), 10.2(6), 10.3(3w), 10.3(99x), 10.3(3o), 10.3(4), 10.3(3p), 10.3(4a), 10.4(2), 10.3(3q), 10.3(5), 10.2(7), 10.4(3), 10.3(3x), 10.3(4g), 10.5(1), 10.2(8), 10.3(3r), 10.3(6), 10.4(4), 10.3(4h), 10.5(2), 10.3(7), 10.4(5), 10.5(3), 10.2(9), 10.4(4g), 10.6(1), 10.5(3t), 10.3(8), 10.4(6), 10.5(3s), 10.5(3e), 10.5(3o), 10.6(1s), 10.5(3p)

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco nx-oscert_advisory90%
cisnexuscert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx

Related News (3 articles)

Tier B
BSI Advisories27d ago
[NEU] [mittel] Cisco Nexus 3000- und 9000-Switches im Standalone-NX-OS-Modus: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier C
VulDB28d ago
CVE-2026-20171 | Cisco NX-OS Software up to 10.6(1s) BGP Enforce-First-As Feature control flow (cisco-sa-bgp-iefab-3hb2pwtx)
→ No new info (linked only)
Tier A
Cisco Security28d ago
Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability
→ No new info (linked only)
CVSS 3.16.8 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-670
PublishedMay 20, 2026
Last enriched28d ago
Trending Score2
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20190EXP
Cisco Identity Services Engine Information Disclosure Vulnerability
Trending: 66
CRITICALCVE-2026-20181EXP
Cisco Identity Services Engine Remote Code Execution Vulnerability
Trending: 65
MEDIUMCVE-2026-20220
Cisco Crosswork Network Controller Remote Code Execution Vulnerability
Trending: 34
CRITICALPRE-CVE
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Trending: 30
MEDIUMCVE-2026-20206
Cisco ThousandEyes BrowserBot Command Injection Vulnerability
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 20, 2026
Discovered by ZDM
May 20, 2026