CVE-2025-20262 Details
Description
A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition. This vulnerability is due to improper processing of PIM6 ephemeral data queries. An attacker could exploit this vulnerability by sending a crafted ephemeral query to an affected device through one of the following methods: NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. A successful exploit could allow the attacker to cause the PIM6 process to crash and restart, causing potential adjacency flaps and resulting in a DoS of the PIM6 and ephemeral query processes.
A denial-of-service vulnerability has been identified in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode. This vulnerability allows an authenticated, low-privileged, remote attacker to crash the PIM6 process, causing it to restart and potentially disrupt network adjacency. The issue arises from improper handling of PIM6 ephemeral data queries. Exploitation can be carried out by sending a crafted ephemeral query to the affected device using NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry.
Cisco has released software updates to address this vulnerability. For guidance on determining the best release for Cisco Nexus Switches, consult the Cisco NX-OS Recommended Releases documents. To check for vulnerabilities in a specific Cisco NX-OS release, use the Cisco Software Checker tool.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 27, 2025CISA-ADP
Assessed Aug 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxospc-pim6-vG4jFPh | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cisco Nexus 3000 | All versions |
CPE
Remediation
| |
| Cisco Nexus 9000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 27, 2025 | New CVE Received | [email protected] |
Volerion