CVE-2024-20321: Cisco NX-OS
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulnerability by sending large amounts of network traffic with certain characteristics through an affected device. A successful exploit could allow the attacker to cause eBGP neighbor sessions to be dropped, leading to a DoS condition in the network.
Affected products
- Cisco NX-OS: version 7.0(3)f1(1) only; version 7.0(3)f2(1) only; version 7.0(3)f2(2) only; version 7.0(3)f3(1) only; version 7.0(3)f3(2) only; version 7.0(3)f3(3) only; …
Published 2024-02-29. Last modified 2026-06-17.