Impact
The vulnerability is an improper input validation flaw in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX‑OS Software, designated NGOAM. It allows an unauthenticated remote attacker to send crafted IP packets to an interface on the switch, leading to arbitrary code execution with root privileges or to a denial of service by causing process crashes that trigger a reload. The weakness is a stack‑based buffer overflow (CWE‑121), which can compromise confidentiality, integrity, and availability by granting full control of the device.
Affected Systems
The affected products are Cisco NX‑OS Software running on Cisco Nexus 9000 Series switches. The advisories indicate that the vulnerability exists when the NGOAM and SRv6 features are enabled. No specific version ranges are provided in the data, so all installations of NX‑OS Software on Nexus 9000 devices that have these features enabled are potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 marks this as critical, and the EPSS score is not available, implying that its exploit probability is currently unknown but potentially high given the remote code execution nature. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered over the network by unauthenticated traffic, the likelihood of exploitation is significant in environments where SRv6/NGOAM is enabled. The attack path requires only sending specially crafted packets to a device IP interface; no user interaction or privileged login is needed.
OpenCVE Enrichment