cbcvebase.

Cisco Nx-Os Software vulnerabilities

88 known vulnerabilities affecting cisco/cisco_nx-os_software.

Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM53

Vulnerabilities

Page 2 of 5
CVE-2020-3517P3HIGHCVSS 8.6vn/a2020-08-27
CVE-2020-3517 [HIGH] CWE-476 CVE-2020-3517: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. For more information about
nvd
CVE-2022-20823P3HIGHCVSS 8.6vn/a2022-08-25
CVE-2022-20823 [HIGH] CWE-126 CVE-2022-20823: A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauth A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending a malicious OSPFv
nvd
CVE-2021-1227P3HIGHCVSS 8.1vn/a2021-02-24
CVE-2021-1227 [HIGH] CWE-352 CVE-2021-1227: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of th
nvd
CVE-2023-20050P3HIGHCVSS 7.8vn/a2023-02-23
CVE-2023-20050 [HIGH] CWE-78 CVE-2023-20050: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including craf
nvd
CVE-2019-1735P3HIGHCVSS 7.8≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1735 [HIGH] CWE-77 CVE-2019-1735: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by in
nvd
CVE-2019-1967P3HIGHCVSS 7.5≥ unspecified, < 8.3(2)2019-08-30
CVE-2019-1967 [HIGH] CWE-399 CVE-2019-1967: A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an un A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources when the affected device is logging a drop action for received MODE_PRIVATE (Mode 7) NTP packe
nvd
CVE-2019-1726P3HIGHCVSS 7.8≥ unspecified, < 6.2(25)≥ unspecified, < 8.3(2)+2 more2019-05-15
CVE-2019-1726 [HIGH] CWE-20 CVE-2019-1726: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to a A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicio
nvd
CVE-2020-3168P3HIGHCVSS 7.5≥ unspecified, < n/a2020-02-26
CVE-2020-3168 [HIGH] CWE-399 CVE-2020-3168: A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware v A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The vulnerability is due to improper resource allocation during failed CLI login attem
nvd
CVE-2025-20241P3HIGHCVSS 7.4v9.2(3)v7.0(3)I5(2)+125 more2025-08-27
CVE-2025-20241 [HIGH] CWE-733 CVE-2025-20241: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Sof A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload
nvd
CVE-2019-1965P3HIGHCVSS 7.7≥ unspecified, < 8.4(1)2019-08-28
CVE-2019-1965 [HIGH] CWE-400 CVE-2019-1965: A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow a A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deplete system memory. When there is no system memory available, this can cause unexpected system be
nvd
CVE-2020-3394P3HIGHCVSS 7.8vn/a2020-08-27
CVE-2020-3394 [HIGH] CWE-285 CVE-2020-3394: A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 900 A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to issue the enable command and get full administrative privileges. To exploit this vulnerability, the attacker would need to have valid credentials for the affected d
nvd
CVE-2026-20171P3MEDIUMCVSS 6.8v10.2(1)v10.2(1q)+47 more2026-05-20
CVE-2026-20171 [MEDIUM] CWE-670 CVE-2026-20171: A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nex A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of
nvd
CVE-2026-20010P3HIGHCVSS 7.4v10.3(1)v10.3(2)+15 more2026-02-25
CVE-2026-20010 [HIGH] CWE-805 CVE-2026-20010: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could al A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit t
nvd
CVE-2023-20169P3HIGHCVSS 7.4v10.3(2)2023-08-23
CVE-2023-20169 [HIGH] CWE-788 CVE-2023-20169: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS So A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to r
nvd
CVE-2025-20191P3HIGHCVSS 7.4v8.2(5)v7.3(5)D1(1)+117 more2025-05-07
CVE-2025-20191 [HIGH] CWE-805 CVE-2025-20191: A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS X A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the incorrect h
nvd
CVE-2026-20051P3HIGHCVSS 7.4v9.2(3)v9.2(2v)+73 more2026-02-25
CVE-2026-20051 [HIGH] CWE-457 CVE-2026-20051: A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 P A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attac
nvd
CVE-2024-20411P3MEDIUMCVSS 6.7v9.2(3)v7.0(3)I5(2)+155 more2024-08-28
CVE-2024-20411 [MEDIUM] CWE-267 CVE-2024-20411: A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device. This vulnerability is due to insufficient security restrictions when executing commands from the Bash shell. An attacker with privileges to access the Bash shell could
nvd
CVE-2025-20111P3HIGHCVSS 7.4v9.3(2)v9.3(1)+51 more2025-02-26
CVE-2025-20111 [HIGH] CWE-1220 CVE-2025-20111: A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco N A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of s
nvd
CVE-2019-1768P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-16
CVE-2019-1768 [MEDIUM] CWE-119 CVE-2019-1768: A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system o
nvd
CVE-2019-1767P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1767 [MEDIUM] CWE-119 CVE-2019-1767: A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system o
nvd
Cisco Nx-Os Software vulnerabilities | cvebase