CVE-2026-20173: Cisco NX-OS Software

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane protocols through some packet loss and temporary disruptions, causing a DoS condition. This DoS condition will clear without manual intervention soon after the high rate of traffic is stopped.

Affected products

  • Cisco Cisco NX-OS Software: version 8.2(5) only; version 7.3(5)D1(1) only; version 8.4(2) only; version 8.4(3) only; version 9.2(3) only; version 9.2(2v) only; …

Published 2026-10-07. Last modified 2026-10-08.