CVE-2026-20010
published 2026-02-25CVE-2026-20010: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP…
PriorityP338high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.17%
6.3th percentile
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol).
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
| cisco | cisco_nx-os_system_software_in_aci_mode | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·2026-02-25·CVSS 7.4
CVE-2026-20010 [HIGH] CWE-805 Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affect
Cisco
Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20010 Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
CVE-2026-20010: Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interfac
GHSA
GHSA-8f59-hcpc-g3hp: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause
ghsa_unreviewed·2026-02-25
CVE-2026-20010 [HIGH] CWE-805 GHSA-8f59-hcpc-g3hp: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.
Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel con
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-25
Published