Cisco Nx-Os Software vulnerabilities
88 known vulnerabilities affecting cisco/cisco_nx-os_software.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM53
Vulnerabilities
Page 3 of 5
CVE-2019-1784P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1784 [MEDIUM] CWE-77 CVE-2019-1784: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this
nvd
CVE-2019-1778P3MEDIUMCVSS 6.7≥ unspecified, < 7.0(3)I7(4)2019-05-15
CVE-2019-1778 [MEDIUM] CWE-78 CVE-2019-1778: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this
nvd
CVE-2019-1776P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1776 [MEDIUM] CWE-78 CVE-2019-1776: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vu
nvd
CVE-2019-1795P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1795 [MEDIUM] CWE-77 CVE-2019-1795: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An atta
nvd
CVE-2019-1780P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-16
CVE-2019-1780 [MEDIUM] CWE-77 CVE-2019-1780: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI com
nvd
CVE-2019-1770P3MEDIUMCVSS 6.7≥ unspecified, < n/a2019-05-15
CVE-2019-1770 [MEDIUM] CWE-78 CVE-2019-1770: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device.
nvd
CVE-2024-20291P3MEDIUMCVSS 5.8v9.3(10)v9.3(11)+1 more2024-02-29
CVE-2024-20291 [MEDIUM] CWE-284 CVE-2024-20291: A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device.
This vulnerability is due to incorrect hardware programming that occurs wh
nvd
CVE-2019-1791P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1791 [MEDIUM] CWE-77 CVE-2019-1791: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could
nvd
CVE-2019-1783P3MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1783 [MEDIUM] CWE-77 CVE-2019-1783: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device.
nvd
CVE-2019-1769P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1769 [MEDIUM] CWE-78 CVE-2019-1769: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system of an attached line card with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command
nvd
CVE-2019-1790P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1790 [MEDIUM] CWE-77 CVE-2019-1790: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with valid administrator credentials to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulne
nvd
CVE-2019-1782P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1782 [MEDIUM] CWE-77 CVE-2019-1782: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by
nvd
CVE-2019-1775P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1775 [MEDIUM] CWE-78 CVE-2019-1775: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious inpu
nvd
CVE-2019-1781P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1781 [MEDIUM] CWE-77 CVE-2019-1781: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by
nvd
CVE-2019-1774P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1774 [MEDIUM] CWE-78 CVE-2019-1774: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious inpu
nvd
CVE-2019-1779P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1779 [MEDIUM] CWE-77 CVE-2019-1779: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploi
nvd
CVE-2019-1728P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1728 [MEDIUM] CWE-347 CVE-2019-1728: A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisc
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration informatio
nvd
CVE-2019-1727P4MEDIUMCVSS 6.7≥ unspecified, < 6.2(25)≥ unspecified, < 8.3(2)+2 more2019-05-15
CVE-2019-1727 [MEDIUM] CWE-264 CVE-2019-1727: A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticat
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions in the s
nvd
CVE-2024-20413P4MEDIUMCVSS 6.7v9.2(3)v7.0(3)I5(2)+157 more2024-08-28
CVE-2024-20413 [MEDIUM] CWE-862 CVE-2024-20413: A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges
A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.
This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access th
nvd
CVE-2025-20161P4MEDIUMCVSS 5.1v9.2(3)v7.0(3)I5(2)+122 more2025-02-26
CVE-2025-20161 [MEDIUM] CWE-78 CVE-2025-20161: A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.
This vulnerability is due to
nvd