<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Network Services Orchestrator - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/network-services-orchestrator/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 07 May 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/network-services-orchestrator/feed.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Crosswork Network Controller and Network Services Orchestrator Connection Exhaustion Denial of Service</title><link>https://feed.craftedsignal.io/briefs/2026-05-cisco-nso-dos/</link><pubDate>Thu, 07 May 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-cisco-nso-dos/</guid><description>An unauthenticated remote attacker can cause a denial-of-service condition on Cisco Crosswork Network Controller and Network Services Orchestrator by exhausting connection resources via a high volume of connection requests.</description><content:encoded><![CDATA[<p>Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) are susceptible to a denial-of-service (DoS) vulnerability due to inadequate rate-limiting on incoming network connections. Exploitation involves an unauthenticated, remote attacker sending a large number of connection requests to an affected system. This can exhaust available connection resources, rendering Cisco CNC and Cisco NSO unresponsive, leading to a DoS condition for legitimate users and dependent services. Recovery requires a manual reboot of the affected system. Cisco has released software updates to address this vulnerability, and no workarounds are available. This vulnerability is identified as CVE-2026-20188.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies a vulnerable Cisco Crosswork Network Controller or Network Services Orchestrator instance exposed to the network.</li>
<li>The attacker establishes multiple TCP connections to the targeted system.</li>
<li>The attacker sends a high volume of connection requests to the targeted system over the established connections.</li>
<li>The targeted system inadequately rate-limits the incoming connection requests.</li>
<li>The flood of connection requests exhausts the available connection resources on the system.</li>
<li>Cisco CNC and Cisco NSO become unresponsive due to resource exhaustion.</li>
<li>Legitimate users and dependent services experience a denial-of-service condition.</li>
<li>The system requires a manual reboot to restore normal operation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to a denial-of-service condition, rendering Cisco Crosswork Network Controller and Cisco Network Services Orchestrator unresponsive. Legitimate users are unable to access the services, and dependent services are disrupted. Recovery requires a manual reboot of the affected system, leading to downtime and potential data loss. The scope of impact depends on the criticality of CNC and NSO within the affected network infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the latest software updates provided by Cisco to patch CVE-2026-20188 on all affected Cisco Crosswork Network Controller and Cisco Network Services Orchestrator instances.</li>
<li>Monitor network connections to Cisco Crosswork Network Controller and Cisco Network Services Orchestrator using the &quot;Cisco NSO/CNC Excessive Connections&quot; Sigma rule to detect potential DoS attacks.</li>
<li>Implement rate-limiting mechanisms on network devices and firewalls to restrict the number of connections from a single source IP address to Cisco Crosswork Network Controller and Cisco Network Services Orchestrator.</li>
<li>Investigate and block any suspicious IP addresses identified by the &quot;Cisco NSO/CNC Single Source Connections&quot; Sigma rule exhibiting unusually high connection attempts.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>cisco</category><category>network</category></item></channel></rss>