📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 1h Global supply_chain Software Development and Technology HIGH 1h Global general Artificial Intelligence and Software Development LOW 2h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h
Vulnerabilities

CVE-2026-20188

High
CWE-400 — Weakness Type
Published: May 6, 2026  ·  Modified: May 13, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

A vulnerability in the connection-handling mechanism of Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.

This vulnerability is due to an inadequate implementation of rate-limiting on incoming network connections. An attacker could exploit this vulnerability by sending a large number of connection requests to an affected system. A successful exploit could allow the attacker to exhaust available connection resources, causing Cisco CNC and Cisco NSO to become unresponsive and resulting in a DoS condition for legitimate users and dependent services. A manual reboot of the system is required to recover from this condition.

🤖 AI Executive Summary

CVE-2026-20188 is a high-severity denial of service vulnerability affecting Cisco Crosswork Network Controller and Network Services Orchestrator due to inadequate rate-limiting on incoming connections. An unauthenticated remote attacker can exhaust connection resources by sending numerous connection requests, rendering affected systems unresponsive and requiring manual reboot for recovery. With no patch currently available and no exploit publicly disclosed, organizations should implement immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 11, 2026 10:33
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi telecommunications infrastructure (STC, Mobily, Zain) and government networks that rely on Cisco CNC/NSO for network orchestration and management. Critical impact on ARAMCO's network operations, SAMA's financial infrastructure connectivity, and NCA's government network management systems. Healthcare sector networks using these controllers for service delivery orchestration are also at risk. The DoS condition could disrupt critical services, requiring manual intervention and causing extended downtime in mission-critical environments.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Energy (ARAMCO, SEC) Banking and Finance (SAMA, commercial banks) Government (NCA, ministries) Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of Cisco CNC and NSO in your environment and document their criticality and network exposure
2. Implement network-level rate-limiting on all ingress connections to CNC/NSO systems using firewall rules (limit connection attempts per source IP to 100 connections/minute)
3. Restrict administrative access to CNC/NSO management interfaces to authorized networks only using ACLs
4. Enable connection timeout settings to aggressive values (30-60 seconds for idle connections)
5. Implement DDoS mitigation at network perimeter using rate-limiting and connection state tracking

COMPENSATING CONTROLS:
6. Deploy reverse proxy/load balancer in front of CNC/NSO with built-in rate-limiting and connection pooling
7. Configure IDS/IPS signatures to detect abnormal connection patterns (threshold: >500 connections/minute from single source)
8. Implement NetFlow/sFlow monitoring to detect connection exhaustion attacks in real-time
9. Set up automated alerting when connection queue utilization exceeds 70%
10. Establish manual intervention procedures for rapid system restart if DoS detected

DETECTION RULES:
- Alert on source IPs establishing >100 connections within 60-second window
- Monitor CNC/NSO process memory and connection table for anomalies
- Track failed connection attempts and sudden spikes in connection reset events

PATCHING:
11. Subscribe to Cisco security advisories for patch availability
12. Prepare change management procedures for immediate patching upon release
13. Maintain test environment for patch validation before production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع حالات Cisco CNC و NSO في بيئتك وتوثيق أهميتها والتعرض للشبكة
2. تنفيذ تحديد معدل على مستوى الشبكة لجميع الاتصالات الواردة إلى أنظمة CNC/NSO باستخدام قواعد جدار الحماية (تحديد محاولات الاتصال إلى 100 اتصال/دقيقة)
3. تقييد الوصول الإداري إلى واجهات إدارة CNC/NSO للشبكات المصرح بها فقط باستخدام قوائم التحكم في الوصول
4. تفعيل إعدادات انتهاء انتظار الاتصال بقيم عدوانية (30-60 ثانية للاتصالات الخاملة)
5. تنفيذ تخفيف DDoS على محيط الشبكة باستخدام تحديد المعدل وتتبع حالة الاتصال

الضوابط التعويضية:
6. نشر وكيل عكسي/موازن حمل أمام CNC/NSO مع تحديد معدل مدمج وتجميع الاتصالات
7. تكوين توقيعات IDS/IPS للكشف عن أنماط الاتصال غير الطبيعية (الحد الأدنى: >500 اتصال/دقيقة من مصدر واحد)
8. تنفيذ مراقبة NetFlow/sFlow للكشف عن هجمات استنزاف الاتصال في الوقت الفعلي
9. إعداد التنبيهات الآلية عند تجاوز استخدام قائمة انتظار الاتصال 70%
10. إنشاء إجراءات التدخل اليدوي لإعادة تشغيل النظام السريعة عند اكتشاف DoS

قواعد الكشف:
- تنبيه على عناوين IP المصدر التي تنشئ >100 اتصال خلال نافذة 60 ثانية
- مراقبة ذاكرة عملية CNC/NSO وجدول الاتصال للشذوذ
- تتبع محاولات الاتصال الفاشلة والارتفاعات المفاجئة في أحداث إعادة تعيين الاتصال

التصحيح:
11. الاشتراك في تنبيهات أمان Cisco لتوفر التصحيح
12. تحضير إجراءات إدارة التغيير للتصحيح الفوري عند الإصدار
13. الحفاظ على بيئة اختبار للتحقق من صحة التصحيح قبل نشر الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.2.1 - Change management procedures ECC 2024 A.13.1.3 - Segregation of networks ECC 2024 A.13.2.1 - Access control to network services
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.AC-3 - Access control and authentication mechanisms PR.PT-1 - Security awareness and training for DoS mitigation DE.CM-1 - Detection and monitoring of anomalous activity
🟡 ISO 27001:2022
A.12.3.1 - Segregation of networks A.13.1.3 - Segregation of information networks A.14.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 11.2 - Vulnerability scanning and assessment
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-400
EPSS0.11%
Exploit No
Patch ✗ No
Published 2026-05-06
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-400
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.