CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access to the connected switch to be able to send custom TCP packets to the CVX.
References
Configurations
No configuration.
History
05 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-05 17:16
Updated : 2026-06-05 19:03
NVD link : CVE-2025-5090
Mitre link : CVE-2025-5090
CVE.ORG link : CVE-2025-5090
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
