Cisco Nx-Os Software vulnerabilities
87 known vulnerabilities affecting cisco/cisco_nx-os_software.
Total CVEs
87
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM52
Vulnerabilities
Page 1 of 5
CVE-2026-20010HIGHCVSS 7.4v10.3(1)v10.3(2)+15 more2026-02-25
CVE-2026-20010 [HIGH] CWE-805 CVE-2026-20010: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could al
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit t
cvelistv5nvd
CVE-2026-20051HIGHCVSS 7.4v9.2(3)v9.2(2v)+73 more2026-02-25
CVE-2026-20051 [HIGH] CWE-457 CVE-2026-20051: A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 P
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop.
This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attac
cvelistv5nvd
CVE-2025-20241HIGHCVSS 7.4v9.2(3)v7.0(3)I5(2)+125 more2025-08-27
CVE-2025-20241 [HIGH] CWE-733 CVE-2025-20241: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Sof
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload
cvelistv5nvd
CVE-2025-20290MEDIUMCVSS 5.5v9.2(3)v7.0(3)I5(2)+111 more2025-08-27
CVE-2025-20290 [MEDIUM] CWE-200 CVE-2025-20290: A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches,
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive
cvelistv5nvd
CVE-2025-20292MEDIUMCVSS 4.4v8.2(5)v7.3(6)N1(1a)+220 more2025-08-27
CVE-2025-20292 [MEDIUM] CWE-78 CVE-2025-20292: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command injection attack on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
This vulnerability is due to insufficient validation of us
cvelistv5nvd
CVE-2025-20262MEDIUMCVSS 5.0v9.2(3)v9.2(2v)+62 more2025-08-27
CVE-2025-20262 [MEDIUM] CWE-476 CVE-2025-20262: A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 S
A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition.
This vulnerability is
cvelistv5nvd
CVE-2025-20191HIGHCVSS 7.4v8.2(5)v7.3(5)D1(1)+117 more2025-05-07
CVE-2025-20191 [HIGH] CWE-805 CVE-2025-20191: A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS X
A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to the incorrect h
cvelistv5nvd
CVE-2025-20111HIGHCVSS 7.4v9.3(2)v9.3(1)+51 more2025-02-26
CVE-2025-20111 [HIGH] CWE-1220 CVE-2025-20111: A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco N
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to the incorrect handling of s
cvelistv5nvd
CVE-2025-20161MEDIUMCVSS 5.1v9.2(3)v7.0(3)I5(2)+122 more2025-02-26
CVE-2025-20161 [MEDIUM] CWE-78 CVE-2025-20161: A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.
This vulnerability is due to
cvelistv5nvd
CVE-2024-20397MEDIUMCVSS 5.2v8.2(5)v7.3(5)D1(1)+183 more2024-12-04
CVE-2024-20397 [MEDIUM] CWE-284 CVE-2024-20397: A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker wi
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.
This vulnerability is due to insecure bootloader settings. An attacker could exploit this vul
cvelistv5nvd
CVE-2024-20284HIGHCVSS 8.8v8.2(5)v7.3(6)N1(1a)+318 more2024-08-28
CVE-2024-20284 [MEDIUM] CWE-693 CVE-2024-20284: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
cvelistv5nvd
CVE-2024-20286HIGHCVSS 8.8v8.2(5)v7.3(5)D1(1)+270 more2024-08-28
CVE-2024-20286 [MEDIUM] CWE-693 CVE-2024-20286: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
cvelistv5nvd
CVE-2024-20446HIGHCVSS 8.6v10.2(1)v10.2(1q)+2 more2024-08-28
CVE-2024-20446 [HIGH] CWE-476 CVE-2024-20446: A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, re
A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in a DHCPv6 RELAY-REPLY message. An attacker could exploit this vulnerability by sending a crafted DHCPv
cvelistv5nvd
CVE-2024-20285HIGHCVSS 8.8v7.3(6)N1(1a)v8.4(2)+256 more2024-08-28
CVE-2024-20285 [MEDIUM] CWE-653 CVE-2024-20285: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
cvelistv5nvd
CVE-2024-20413MEDIUMCVSS 6.7v9.2(3)v7.0(3)I5(2)+157 more2024-08-28
CVE-2024-20413 [MEDIUM] CWE-862 CVE-2024-20413: A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges
A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.
This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access th
cvelistv5nvd
CVE-2024-20289MEDIUMCVSS 4.4v9.3(3)v9.3(4)+40 more2024-08-28
CVE-2024-20289 [MEDIUM] CWE-78 CVE-2024-20289: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, loc
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including
cvelistv5nvd
CVE-2024-20411MEDIUMCVSS 6.7v9.2(3)v7.0(3)I5(2)+155 more2024-08-28
CVE-2024-20411 [MEDIUM] CWE-267 CVE-2024-20411: A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges
A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device.
This vulnerability is due to insufficient security restrictions when executing commands from the Bash shell. An attacker with privileges to access the Bash shell could
cvelistv5nvd
CVE-2024-20399MEDIUMCVSS 6.7KEVv8.2(5)v7.3(6)N1(1a)+316 more2024-07-01
CVE-2024-20399 [MEDIUM] CWE-78 CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession o
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An at
cvelistv5nvd
CVE-2024-20321HIGHCVSS 8.6v7.0(3)F1(1)v7.0(3)F2(1)+46 more2024-02-29
CVE-2024-20321 [HIGH] CWE-400 CVE-2024-20321: A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Softwar
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulner
cvelistv5nvd
CVE-2024-20267HIGHCVSS 8.6v6.0(2)A3(1)v6.0(2)A3(2)+203 more2024-02-29
CVE-2024-20267 [HIGH] CWE-120 CVE-2024-20267: A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenti
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload.
This vulnerability is due to lack of proper error checking when processing an ingress MPLS frame.
cvelistv5nvd
1 / 5Next →