Cisco Security Advisory
Follow
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability
Cisco CNC and NSO are affected by a security vulnerability related to their connection handling. This flaw stems from a deficient rate-limiting mechanism for incoming network connections. An attacker can exploit this by flooding the system with numerous connection requests. This action can deplete the available connection resources. This would ultimately lead to Cisco CNC and NSO becoming unresponsive. The result is a denial-of-service (DoS) for legitimate users and reliant services. A system reboot is necessary to restore functionality after such an attack. Cisco has issued software updates to resolve this vulnerability. There are no available workarounds to mitigate this issue. The security impact of this vulnerability is rated as High. The vulnerability is tracked under CVE-2026-20188.