Cisco Nx-Os Software vulnerabilities
88 known vulnerabilities affecting cisco/cisco_nx-os_software.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM53
Vulnerabilities
Page 4 of 5
CVE-2019-1732P4MEDIUMCVSS 6.4≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1732 [MEDIUM] CWE-78 CVE-2019-1732: A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to arbitrary command injection. The vulnerability is due to the lack of a proper l
nvd
CVE-2025-20292P4MEDIUMCVSS 4.4v8.2(5)v7.3(6)N1(1a)+220 more2025-08-27
CVE-2025-20292 [MEDIUM] CWE-78 CVE-2025-20292: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command injection attack on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
This vulnerability is due to insufficient validation of us
nvd
CVE-2023-20115P4MEDIUMCVSS 5.4v9.2(1)v9.2(2)+28 more2023-08-23
CVE-2023-20115 [MEDIUM] CWE-671 CVE-2023-20115: A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Seri
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device.
This vulnerability is due to a logic error when verifying the user role when
nvd
CVE-2019-1730P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1730 [MEDIUM] CWE-264 CVE-2019-1730: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticat
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside of the Guest Shell. The attacker must authenticate with valid administrator device credentials
nvd
CVE-2019-1810P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1810 [MEDIUM] CWE-347 CVE-2019-1810: A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Ne
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not
nvd
CVE-2019-1969P4MEDIUMCVSS 5.3≥ unspecified, < 9.2(3)2019-08-30
CVE-2019-1969 [MEDIUM] CWE-264 CVE-2019-1969: A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Contro
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic. The vulnerability is due to an incorrect length check when the con
nvd
CVE-2021-1591P4MEDIUMCVSS 5.3vn/a2021-08-25
CVE-2021-1591 [MEDIUM] CWE-284 CVE-2021-1591: A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches coul
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of resources that occurs when applying ACLs to port channel interfaces. An att
nvd
CVE-2019-1812P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1812 [MEDIUM] CWE-347 CVE-2019-1812: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1813P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1813 [MEDIUM] CWE-347 CVE-2019-1813: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1811P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1811 [MEDIUM] CWE-347 CVE-2019-1811: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1809P4MEDIUMCVSS 6.7≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1809 [MEDIUM] CWE-347 CVE-2019-1809: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulne
nvd
CVE-2021-1590P4MEDIUMCVSS 5.3vn/a2021-08-25
CVE-2021-1590 [MEDIUM] CWE-787 CVE-2021-1590: A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when a
nvd
CVE-2019-1733P4MEDIUMCVSS 5.4≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1733 [MEDIUM] CWE-79 CVE-2019-1733: A vulnerability in the NX API (NX-API) Sandbox interface for Cisco NX-OS Software could allow an aut
A vulnerability in the NX API (NX-API) Sandbox interface for Cisco NX-OS Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the NX-API Sandbox interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the NX-API Sandbox interface. A
nvd
CVE-2019-1734P4MEDIUMCVSS 5.5≥ unspecified, < 6.2(7)2019-11-05
CVE-2019-1734 [MEDIUM] CWE-200 CVE-2019-1734: A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco N
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based
nvd
CVE-2024-20397P4MEDIUMCVSS 5.2v8.2(5)v7.3(5)D1(1)+183 more2024-12-04
CVE-2024-20397 [MEDIUM] CWE-284 CVE-2024-20397: A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker wi
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.
This vulnerability is due to insecure bootloader settings. An attacker could exploit this vul
nvd
CVE-2025-20262P4MEDIUMCVSS 5.0v9.2(3)v9.2(2v)+62 more2025-08-27
CVE-2025-20262 [MEDIUM] CWE-476 CVE-2025-20262: A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 S
A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition.
This vulnerability is
nvd
CVE-2019-1595P4MEDIUMCVSS 6.5v7.3(5)N1(1)2019-03-06
CVE-2019-1595 [MEDIUM] CWE-913 CVE-2019-1595: A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Sof
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an incorrect allocation of an internal interface index. An adjacent attacker with the ability to subm
nvd
CVE-2023-20168P4MEDIUMCVSS 6.5v4.2(1)SV1(4)v4.2(1)SV1(4a)+342 more2023-08-23
CVE-2023-20168 [MEDIUM] CWE-120 CVE-2023-20168: A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An at
nvd
CVE-2019-1729P4MEDIUMCVSS 6.0≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1729 [MEDIUM] CWE-20 CVE-2019-1729: A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, local attacker to overwrite any file on the file system including system files. These file overwrites by the attacker are accomplished at the root privilege level. The vulnerability occurs because there is no
nvd
CVE-2025-20290P4MEDIUMCVSS 5.5v9.2(3)v7.0(3)I5(2)+111 more2025-08-27
CVE-2025-20290 [MEDIUM] CWE-200 CVE-2025-20290: A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches,
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive
nvd