Cisco announced the release of fixes for four vulnerabilities in the FXOS and NX-OS network operating systems, including a denial-of-service (DoS) issue identified by the US National Security Agency (NSA). The most critical is CVE-2022-20650, a command injection vulnerability that can be exploited remotely without authentication to execute arbitrary commands with root privileges. It has a CVSS score of 8.8.

The problem arises because user data is not sufficiently validated, allowing an attacker to send a fake HTTP POST request to the NX-API function on a vulnerable device and execute arbitrary commands. By default, the NX-API function is disabled. The vulnerability affects Nexus 3000, 5500, 5600, 6000, and 9000 series switches if they have unpatched NX-OS software with the NX-API function enabled.

The remaining three vulnerabilities can be used for DoS attacks. In particular, vulnerability CVE-2022-20624, identified by the NSA, is related to the Fabric Services over IP (CFSoIP) feature. The problem arises due to incorrect verification of incoming CFSoIP packets, which allows an attacker to send fake packets and disrupt the system. When the CFSoIP feature is enabled, Nexus 3000 and 9000 switches, as well as UCS 6400 in fabric interconnect mode, are vulnerable. CFSoIP is disabled by default.

Another vulnerability, CVE-2022-20623, is related to the Bidirectional Forwarding Detection (BFD) traffic limiter in NX-OS. It can be exploited remotely, without authentication, to block BFD traffic. Only Nexus 9000 switches running standalone NX-OS are affected. The problem is caused by a logical failure in the BFD traffic restriction function, which can be used to block IPv4 and IPv6 traffic and cause DoS events.

In Multi-Pod and Multi-Site network configurations on Nexus 9000 series switches in ACI mode, Cisco has also released an additional fix for CVE-2021-1586, a DoS vulnerability first addressed in August 2021. It arises from insufficient verification of TCP traffic sent to a specific port, allowing an attacker to transmit fake data.

Cisco recommends that customers update their devices to the latest patches included in the February 2022 FXOS and NX-OS semi-annual security update. According to the company, these vulnerabilities have not been exploited in real-world attacks at this time.