Cisco Nx-Os Software vulnerabilities
88 known vulnerabilities affecting cisco/cisco_nx-os_software.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM53
Vulnerabilities
Page 1 of 5
CVE-2024-20399P1MEDIUMCVSS 6.7KEVv8.2(5)v7.3(6)N1(1a)+316 more2024-07-01
CVE-2024-20399 [MEDIUM] CWE-78 CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession o
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An at
nvd
CVE-2022-20650P2HIGHCVSS 8.8vn/a2022-02-23
CVE-2022-20650 [HIGH] CWE-78 CVE-2022-20650: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to
nvd
CVE-2021-1361P2CRITICALCVSS 9.1vn/a2021-02-24
CVE-2021-1361 [CRITICAL] CWE-552 CVE-2021-1361: A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Se
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenticated, remote attacker to create, delete, or overwrite arbitrary files with root privileges on the device. This
nvd
CVE-2022-20624P3HIGHCVSS 7.5vn/a2022-02-23
CVE-2022-20624 [HIGH] CWE-400 CVE-2022-20624: A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming CFSoIP packets. An attacker could exploit this vulnerability by sending crafted
nvd
CVE-2022-20824P3HIGHCVSS 8.8vn/a2022-08-25
CVE-2022-20824 [HIGH] CWE-121 CVE-2022-20824: A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Softw
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation of specific values that are w
nvd
CVE-2020-3415P3HIGHCVSS 8.8vn/a2020-08-27
CVE-2020-3415 [HIGH] CWE-787 CVE-2020-3415: A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthent
A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability
nvd
CVE-2021-1368P3HIGHCVSS 8.8vn/a2021-02-24
CVE-2021-1368 [HIGH] CWE-787 CVE-2021-1368: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An a
nvd
CVE-2024-20446P3HIGHCVSS 8.6v10.2(1)v10.2(1q)+2 more2024-08-28
CVE-2024-20446 [HIGH] CWE-476 CVE-2024-20446: A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, re
A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in a DHCPv6 RELAY-REPLY message. An attacker could exploit this vulnerability by sending a crafted DHCPv
nvd
CVE-2024-20284P3HIGHCVSS 8.8v8.2(5)v7.3(6)N1(1a)+318 more2024-08-28
CVE-2024-20284 [HIGH] CWE-693 CVE-2024-20284: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2024-20286P3HIGHCVSS 8.8v8.2(5)v7.3(5)D1(1)+270 more2024-08-28
CVE-2024-20286 [HIGH] CWE-693 CVE-2024-20286: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2024-20285P3HIGHCVSS 8.8v7.3(6)N1(1a)v8.4(2)+256 more2024-08-28
CVE-2024-20285 [HIGH] CWE-653 CVE-2024-20285: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2022-20623P3HIGHCVSS 7.5vn/a2022-02-23
CVE-2022-20623 [HIGH] CWE-399 CVE-2022-20623: A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX
A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker cou
nvd
CVE-2020-3397P3HIGHCVSS 8.6vn/a2020-08-27
CVE-2020-3397 [HIGH] CWE-20 CVE-2020-3397: A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of a specific type of BGP MVPN update
nvd
CVE-2021-1587P3HIGHCVSS 8.6vn/a2021-08-25
CVE-2021-1587 [HIGH] CWE-115 CVE-2021-1587: A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific packets with a Transparent Interconnection of Lots of
nvd
CVE-2024-20267P3HIGHCVSS 8.6v6.0(2)A3(1)v6.0(2)A3(2)+203 more2024-02-29
CVE-2024-20267 [HIGH] CWE-120 CVE-2024-20267: A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenti
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload.
This vulnerability is due to lack of proper error checking when processing an ingress MPLS frame.
nvd
CVE-2020-3165P3HIGHCVSS 8.2v9.2(1)2020-02-26
CVE-2020-3165 [HIGH] CWE-798 CVE-2020-3165: A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authen
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability occurs because the BGP MD5 authentication is bypassed if the peer does not have
nvd
CVE-2021-1387P3HIGHCVSS 8.6vn/a2021-02-24
CVE-2021-1387 [HIGH] CWE-401 CVE-2021-1387: A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because the software improperly releases resources when it processes certain IPv6 packets that are destined to an affected device. An attacker could expl
nvd
CVE-2021-1588P3HIGHCVSS 8.6vn/a2021-08-25
CVE-2021-1588 [HIGH] CWE-126 CVE-2021-1588: A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply pac
nvd
CVE-2024-20321P3HIGHCVSS 8.6v7.0(3)F1(1)v7.0(3)F2(1)+46 more2024-02-29
CVE-2024-20321 [HIGH] CWE-400 CVE-2024-20321: A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Softwar
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulner
nvd
CVE-2020-3398P3HIGHCVSS 8.6vn/a2020-08-27
CVE-2020-3398 [HIGH] CWE-20 CVE-2020-3398: A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a BGP session to repeatedly reset, causing a partial denial of service (DoS) condition due to the BGP session being down. The vulnerability is due to incorrect parsing of a specific type
nvd
1 / 5Next →