CVE-2025-20241 Details
Description
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause the unexpected restart of the IS-IS process, which could cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device.
A denial-of-service vulnerability has been identified in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software, specifically for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode. This vulnerability allows an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, potentially leading to a device reload. The issue arises from insufficient input validation when parsing incoming IS-IS packets, allowing an attacker to exploit the vulnerability by sending crafted IS-IS packets to the affected device. Successful exploitation can disrupt IS-IS routing, causing a denial-of-service condition. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device.
Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. To determine the best Cisco NX-OS release for a Nexus switch, consult the Cisco NX-OS Recommended Releases document for the specific switch series.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 27, 2025CISA-ADP
Assessed Aug 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n39k-isis-dos-JhJA8Rfx | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-733 | Compiler Optimization Removal or Modification of Security-critical Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cisco NX-OS | All versions |
CPE
Remediation
| |
| Cisco Nexus 3000 | All versions |
CPE
Remediation
| |
| Cisco Nexus 9000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 27, 2025 | New CVE Received | [email protected] |
Volerion