Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.0 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 and 9000 Series Switches. This flaw could allow an authenticated, low-privileged remote attacker to trigger a denial of service (DoS) condition. No workarounds are available, but Cisco has released software updates to address the issue.

What happened 🕵️‍♂️

A vulnerability in the PIM6 feature of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged remote attacker to crash the PIM6 process. This is due to improper processing of PIM6 ephemeral data queries. An attacker can exploit this vulnerability by sending a crafted ephemeral query through various methods, including NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. Successful exploitation can lead to a DoS condition, causing potential adjacency flaps.

Affected products 🖥️

The vulnerability affects:

  • Cisco Nexus 3000 Series Switches
  • Cisco Nexus 9000 Series Switches

These devices must have the PIM6 feature enabled along with at least one of the following features:

  • NX-API
  • NETCONF
  • RESTCONF
  • gRPC
  • Model Driven Telemetry

Note: The PIM4 feature is not affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available for this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 5.0, indicating a medium level of risk. The exposure is limited to authenticated users, and the impact is primarily on availability due to potential service disruptions. Organizations should prioritize applying the available software updates to mitigate this risk.

Fast facts ⚡

  • Vulnerability: Denial of Service (DoS) in PIM6
  • CVSS Score: 5.0 (Medium)
  • Exploitation: Requires authenticated access
  • Workarounds: None available
  • Affected Features: PIM6 with NX-API, NETCONF, RESTCONF, gRPC, or Model Driven Telemetry enabled

For leadership 🧭

Executive summary. Nexus 3000 and 9000 switches running PIM6 alongside management interfaces such as NX-API, NETCONF, RESTCONF, gRPC or telemetry can have their PIM6 process crashed by any authenticated user, disrupting IPv6 multicast routing until it recovers. There is no workaround, so this should be scheduled for patching at the next maintenance window rather than treated as an emergency.

Why it matters:

  • Any authenticated, low-privileged user with access to NX-API, NETCONF, RESTCONF, gRPC or Model Driven Telemetry can crash the PIM6 process without needing elevated privileges.
  • A crash of PIM6 flaps multicast adjacencies, disrupting IPv6 multicast routing on the affected Nexus 3000 or 9000 switch.
  • No workaround exists, so switches with PIM6 and any of the affected management features enabled remain exposed until the software is upgraded.
  • PIM4 is unaffected, so the risk is specific to environments running IPv6 multicast via PIM6 on these switch families.

Now / Next / Later:

  • Now: Identify which Nexus 3000 and 9000 switches have PIM6 enabled together with NX-API, NETCONF, RESTCONF, gRPC or Model Driven Telemetry, and review who holds authenticated access to those management interfaces.
  • Next: Upgrade the identified switches to the first fixed NX-OS release for their train during the next available change window, since no workaround exists.
  • Later: Restrict which accounts and network paths can reach NX-API, NETCONF, RESTCONF, gRPC and telemetry interfaces on multicast-enabled switches, and keep NX-OS on switches running PIM6 on a regular patch cycle.