Cisco has released a semiannual security advisory bundle for its FXOS and NX-OS software, addressing four vulnerabilities, two of which are high-severity. The first high-severity issue, CVE-2024-20321, allows an unauthenticated attacker to send excessive traffic, potentially causing a denial-of-service (DoS) condition. This flaw affects certain Nexus switches and line cards. The second high-severity vulnerability, CVE-2024-20267, could lead to a DoS condition by processing an improperly checked ingress MPLS frame. This issue impacts Nexus switches with MPLS configured. Cisco has also patched two medium-severity vulnerabilities, one affecting the LLDP service and another related to ACL programming. The patches are available for NX-OS software versions 9.3(12), 10.2(6), and 10.3(4a).
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
#cybersecurity #cisco #vulnerability #fxos #nxos #cve #dos #patch