Description
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Published: 2026-10-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the MPLS Operation, Administration, and Maintenance (OAM) handling in Cisco NX-OS Software allows an unauthenticated attacker to send a crafted MPLS echo‑request packet, leading to improper validation that can cause arbitrary code execution with root privileges or a denial‑of‑service condition when the offending process crashes. This is a classic example of CWE‑590, where an attacker exploits the execution of untrusted code paths.

Affected Systems

The affected platforms are Cisco NX‑OS Software running on Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches. No specific version range is given, so all current releases that have not applied a patch are considered vulnerable.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical, indicating that an attacker can remotely achieve full control of the device. EPSS data is not available, but the high CVSS and lack of enforcement limits suggest that the risk remains high. The vulnerability is unauthenticated and network‑directed, meaning any external host that can reach the switch IP space can craft the exploit packet. The assignment of a KEV status of ‘not listed’ does not diminish the potential for exploitation if a public exploit were discovered.

Generated by OpenCVE AI on October 7, 2026 at 18:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco NX‑OS Software update that resolves the MPLS echo‑request issue for Nexus 3000 and Nexus 9000 series switches.
  • If a patch is not currently available for the device in use, disable MPLS OAM functionality or restrict the processing of MPLS echo‑requests to trusted interfaces only.
  • Use network segmentation and firewall rules to block unsolicited MPLS echo‑requests and monitor for anomalous traffic patterns that could indicate an attempted exploit.

Generated by OpenCVE AI on October 7, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Title Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
Weaknesses CWE-590
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T17:44:53.620Z

Reserved: 2026-08-19T12:02:03.637Z

Link: CVE-2026-76465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T17:16:59.350

Modified: 2026-10-07T18:17:28.580

Link: CVE-2026-76465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:15:14Z

Weaknesses
  • CWE-590

    Free of Memory not on the Heap