Cisco Nx-Os Software vulnerabilities
88 known vulnerabilities affecting cisco/cisco_nx-os_software.
Total CVEs
88
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH34MEDIUM53
Vulnerabilities
Page 5 of 5
CVE-2024-20294P4MEDIUMCVSS 6.6v6.0(2)A3(1)v6.0(2)A3(2)+292 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2021-1229P4MEDIUMCVSS 5.3vn/a2021-02-24
CVE-2021-1229 [MEDIUM] CWE-401 CVE-2021-1229: A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthe
A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to improper error handling when an IPv6-configured interface receives a specific type of ICMPv6 pa
nvd
CVE-2024-20289P4MEDIUMCVSS 4.4v9.3(3)v9.3(4)+40 more2024-08-28
CVE-2024-20289 [MEDIUM] CWE-78 CVE-2024-20289: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, loc
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including
nvd
CVE-2022-20625P4MEDIUMCVSS 4.3vn/a2022-02-23
CVE-2022-20625 [MEDIUM] CWE-399 CVE-2022-20625: A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Softw
A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisc
nvd
CVE-2018-0395P4MEDIUMCVSS 5.3≥ unspecified, < 6.2(1)2018-10-17
CVE-2018-0395 [MEDIUM] CWE-20 CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software a
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields
nvd
CVE-2019-1808P4MEDIUMCVSS 4.4≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1808 [MEDIUM] CWE-347 CVE-2019-1808: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulne
nvd
CVE-2021-1367P4MEDIUMCVSS 4.3vn/a2021-02-24
CVE-2021-1367 [MEDIUM] CWE-20 CVE-2021-1367: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could al
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an a
nvd
CVE-2019-1731P4MEDIUMCVSS 4.4≥ unspecified, < 8.3(1)2019-05-15
CVE-2019-1731 [MEDIUM] CWE-200 CVE-2019-1731: A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an a
A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an authenticated, local attacker to expose a user's private SSH key to all authenticated users on the targeted device. The attacker must authenticate with valid administrator device credentials. The vulnerability is due to incomplete error handling if a spe
nvd
← Previous5 / 5