#VU123287 Use of uninitialized variable in Cisco NX-OS - CVE-2026-20051
Published: February 26, 2026
Cisco NX-OS
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to improper input validation of the Ethernet VPN (EVPN) Layer 2 ingress packets. A remote attacker on the local network send specially crafted packets to the system, cause a Layer 2 Virtual eXtensible LAN (VxLAN) traffic loop and perform a denial of service attack.