CVE-2017-4920: VMware Nsx-V Edge

Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.

The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may exploit this issue resulting in continuous sending of LSAs between two routers eventually going in loop or loss of connectivity.

Affected products

  • VMware Nsx-V Edge: from 6.2.0, before 6.2.8 (fixed in 6.2.8); from 6.3.0, before 6.3.3 (fixed in 6.3.3)

Published 2017-12-05. Last modified 2026-06-17.