CVE-2025-20241: Cisco Nexus 3000 and 9000 Series Switches IS-IS Protocol <TBD> Denial of Service Vulnerability
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause the unexpected restart of the IS-IS process, which could cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20241?
CVE-2025-20241 is categorized as a high severity vulnerability that affects the IS-IS feature in Cisco Nexus 3000 and 9000 Series Switches.
How can I mitigate CVE-2025-20241?
To mitigate CVE-2025-20241, upgrading to the latest version of Cisco NX-OS Software that addresses this vulnerability is recommended.
Who is affected by CVE-2025-20241?
CVE-2025-20241 affects users of Cisco Nexus 3000 and 9000 Series Switches running in standalone NX-OS mode.
What type of attack does CVE-2025-20241 enable?
CVE-2025-20241 allows an unauthenticated, adjacent attacker to disrupt the IS-IS process, potentially leading to a denial-of-service condition.
Is there a workaround for CVE-2025-20241?
Currently, there are no documented workarounds for CVE-2025-20241 other than applying the software update.