CVE-2025-20111: Cisco Nexus 3000 and 9000 Series Switches Layer 2 Ethernet Denial of Service Vulnerability
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20111?
CVE-2025-20111 is classified as a high severity vulnerability that can lead to denial of service for affected devices.
How can I fix CVE-2025-20111?
To address CVE-2025-20111, it is recommended to apply the latest firmware updates available from Cisco for the affected Nexus switches.
Which devices are affected by CVE-2025-20111?
CVE-2025-20111 affects Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches operating in standalone NX-OS mode.
What are the potential impacts of CVE-2025-20111?
The vulnerability could allow an unauthenticated adjacent attacker to cause the device to unexpectedly reload, resulting in a denial of service.
Is authentication required to exploit CVE-2025-20111?
No, CVE-2025-20111 can be exploited by an unauthenticated attacker who is adjacent to the affected network device.