Executive brief
Cisco has reclassified a previously reported security vulnerability in its Crosswork Network Controller and Network Services Orchestrator as a non-security resource management issue. Originally thought to be a flaw allowing attackers to crash the system, further analysis determined the behavior is related to how customers configure system resources. There is no security risk to customer data or operations beyond standard performance tuning and resource allocation requirements.
Technical details
Initially reported as a denial of service (DoS) vulnerability (CWE-400) due to inadequate rate-limiting on incoming network connections, Cisco PSIRT has since reclassified this issue. The behavior, which could lead to resource exhaustion and require a manual reboot, was determined to be a matter of system sizing and resource management rather than a flaw in the software's security architecture. The CVSS score has been updated to 0.0 as the condition is dependent on customer-controlled resource allocation and performance optimization settings. No patch is required, but Cisco recommends following official documentation for scaling RAM and disk resources in large-scale deployments.
Affected products
- Cisco Crosswork Network Controller
- Cisco Network Services Orchestrator (NSO)
Timeline
- 2026-05-06: disclosed: Initial public release of the advisory.
- 2026-05-14: other: Advisory updated to reclassify the issue from a security vulnerability to an informational resource management issue.