Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 1 of 12
CVE-2024-20284HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20284 [MEDIUM] CWE-693 CVE-2024-20284: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
nvd
CVE-2024-20286HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20286 [MEDIUM] CWE-693 CVE-2024-20286: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
nvd
CVE-2024-20285HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20285 [MEDIUM] CWE-653 CVE-2024-20285: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerab
nvd
CVE-2024-20399MEDIUMCVSS 6.7KEVv6.2\(2\)v6.2\(2a\)+260 more2024-07-01
CVE-2024-20399 [MEDIUM] CWE-78 CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession o A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An at
nvd
CVE-2024-20321HIGHCVSS 8.6v7.0\(3\)f1\(1\)v7.0\(3\)f2\(1\)+46 more2024-02-29
CVE-2024-20321 [HIGH] CWE-400 CVE-2024-20321: A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Softwar A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulner
nvd
CVE-2024-20267HIGHCVSS 8.6v6.0\(2\)a3\(1\)v6.0\(2\)a3\(2\)+203 more2024-02-29
CVE-2024-20267 [HIGH] CWE-120 CVE-2024-20267: A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenti A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload. This vulnerability is due to lack of proper error checking when processing an ingress MPLS frame.
nvd
CVE-2024-20294MEDIUMCVSS 6.6v12.0\(1m\)v12.0\(1n\)+456 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2024-20291MEDIUMCVSS 5.8v9.3\(10\)v9.3\(11\)+1 more2024-02-29
CVE-2024-20291 [MEDIUM] CWE-284 CVE-2024-20291: A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs wh
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoCfixed in 10.2\(7\)≥ 10.3\(1\), < 10.3\(5\)+1 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-20169HIGHCVSS 7.4v10.3\(2\)2023-08-23
CVE-2023-20169 [HIGH] CWE-788 CVE-2023-20169: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS So A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to r
nvd
CVE-2023-20115MEDIUMCVSS 5.4v9.2\(1\)v9.2\(2\)+28 more2023-08-23
CVE-2023-20115 [MEDIUM] CWE-671 CVE-2023-20115: A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Seri A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when
nvd
CVE-2023-20168MEDIUMCVSS 6.5v9.3\(11\)v10.2\(5\)2023-08-23
CVE-2023-20168 [HIGH] CWE-120 CVE-2023-20168: A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An atta
nvd
CVE-2023-20185HIGHCVSS 7.4v14.0\(1h\)v14.0\(2c\)+74 more2023-07-12
CVE-2023-20185 [HIGH] CWE-330 CVE-2023-20185: A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series F A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on af
nvd
CVE-2023-20050HIGHCVSS 7.8fixed in 8.2\(9\)fixed in 9.3\(10\)+1 more2023-02-23
CVE-2023-20050 [MEDIUM] CWE-78 CVE-2023-20050: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including cr
nvd
CVE-2023-20089MEDIUMCVSS 6.5v15.2\(1g\)v15.2\(2e\)+14 more2023-02-23
CVE-2023-20089 [HIGH] CWE-789 CVE-2023-20089: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabr A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due to incorrect error checking when p
nvd
CVE-2022-20623HIGHCVSS 7.5≥ 7.0\(3\)i6\(2\), ≤ 7.0\(3\)i7\(3\)≥ 7.0\(3\)i6\(2\), ≤ 9.3\(8\)+1 more2022-02-23
CVE-2022-20623 [HIGH] CWE-399 CVE-2022-20623: A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker cou
nvd
CVE-2022-20624HIGHCVSS 7.5v7.0\(3\)v9.2\(2\)+4 more2022-02-23
CVE-2022-20624 [HIGH] CWE-400 CVE-2022-20624: A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming CFSoIP packets. An attacker could exploit this vulnerability by sending crafted
nvd
CVE-2022-20650HIGHCVSS 8.8v10.2\(1.72\)v7.3\(8\)n1\(0.4\)2022-02-23
CVE-2022-20650 [HIGH] CWE-78 CVE-2022-20650: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to
nvd
CVE-2022-20625MEDIUMCVSS 4.3v8.2\(7.34\)v5.2\(1\)sv5\(1.3b\)+3 more2022-02-23
CVE-2022-20625 [MEDIUM] CWE-399 CVE-2022-20625: A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Softw A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisc
nvd
CVE-2021-34714HIGHCVSS 7.4≤ 8.4\(3.115\)≤ 7.0\(3\)i7\(9\)+2 more2021-09-23
CVE-2021-34714 [HIGH] CWE-20 CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IO A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An att
nvd
1 / 12Next →