{"id":"CVE-2026-20173","title":"A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.\r\n\r\nThis vulnerability exists because rate limiting was improperly applied t…","summary":"A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.\r\n\r\nThis vulnerability exists because rate limiting was improperly applied t…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","cwe":["CWE-770"],"vendor":"Cisco","product":"Cisco NX-OS Software","affected":["nx-os_software 8.2(5)","nx-os_software 7.3(5)D1(1)","nx-os_software 8.4(2)","nx-os_software 8.4(3)","nx-os_software 9.2(3)","nx-os_software 9.2(2v)","nx-os_software 7.3(4)D1(1)","nx-os_software 8.2(1)","nx-os_software 9.2(1)","nx-os_software 9.2(2t)","nx-os_software 9.2(3y)","nx-os_software 9.3(2)","nx-os_software 8.1(1)","nx-os_software 8.2(2)","nx-os_software 8.3(2)","nx-os_software 7.3(2)D1(3a)","nx-os_software 9.2(4)","nx-os_software 8.1(2)","nx-os_software 7.3(3)D1(1)","nx-os_software 8.2(3)","nx-os_software 8.4(1)","nx-os_software 7.3(0)DX(1)","nx-os_software 7.3(2)D1(1)","nx-os_software 9.3(1)","nx-os_software 7.3(2)D1(2)","nx-os_software 8.2(4)","nx-os_software 9.3(1z)","nx-os_software 9.2(2)","nx-os_software 8.1(2a)","nx-os_software 7.3(2)D1(3)","nx-os_software 8.3(1)","nx-os_software 7.3(1)D1(1)","nx-os_software 7.3(0)D1(1)","nx-os_software 9.3(3)","nx-os_software 7.3(2)D1(1d)","nx-os_software 9.3(4)","nx-os_software 7.3(6)D1(1)","nx-os_software 8.2(6)","nx-os_software 9.3(5)","nx-os_software 9.3(6)","nx-os_software 8.4(4)","nx-os_software 7.3(7)D1(1)","nx-os_software 9.3(5w)","nx-os_software 8.2(7)","nx-os_software 9.3(7)","nx-os_software 9.3(7k)","nx-os_software 7.3(8)D1(1)","nx-os_software 9.3(7a)","nx-os_software 8.2(7a)","nx-os_software 9.3(8)"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:17:19.937","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20173","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-nscpdos-SnderkC7","label":"psirt@cisco.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-07T17:42:18.044011Z"},"ingestedAt":"2026-10-07T16:38:22.255Z","slug":"CVE-2026-20173","body":"## Overview\n\nA vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.\r\n\r\nThis vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane protocols through some packet loss and temporary disruptions, causing a DoS condition. This DoS condition will clear without manual intervention soon after the high rate of traffic is stopped.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}