GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS (eBGP implementation): FABRIC DOS: an unauthenticated remote attacker can wedge the switch through the eBGP

CVE-2024-20321Firmware, BMC & network fabriccurated

Impact

FABRIC DOS: an unauthenticated remote attacker can wedge the switch through the eBGP implementation. In a BGP-underlay leaf/spine — the standard GPU-cluster design — the routing daemon going down means the rack loses reachability, and a coordinated attack against several leaves partitions the fabric mid-training-run.

Who can reach it

Unauthenticated, remote to the BGP process. Requires the ability to reach the switch's BGP listener.

What to do

NX-OS upgrade plus reload. Harden with strict neighbor ACLs and CoPP in the meantime — live config. Because this affects the underlay control plane, schedule the reload per MLAG/ECMP pair so the fabric never loses both paths.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.