Remote Bypass in Cisco Nexus 9000 Series Fabric Switches EPG Functionality
CVE-2026-20038
5.8MEDIUM
What is CVE-2026-20038?
A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode allows an unauthenticated remote attacker to bypass configured EPG contracts. This issue arises from improper controls associated with EPG contracts. An attacker can exploit this flaw by sending crafted IPv4 or IPv6 packets using UDP ports typically associated with DHCP traffic. If successfully executed, this exploitation enables the attacker to bypass EPG contracts, potentially compromising the security of the affected device.
Affected Version(s)
Cisco NX-OS System Software in ACI Mode 15.2(1g)
Cisco NX-OS System Software in ACI Mode 15.2(2e)
Cisco NX-OS System Software in ACI Mode 15.2(2f)