Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 1 of 12
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 10.2\(7\)≥ 10.3\(1\), < 10.3\(5\)+1 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2024-20399P1MEDIUMCVSS 6.7KEVv6.2\(2\)v6.2\(2a\)+260 more2024-07-01
CVE-2024-20399 [MEDIUM] CWE-78 CVE-2024-20399: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession o
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An at
nvd
CVE-2016-1409P2HIGHCVSS 7.5Exploitedv1.0\(1.110a\)v1.0\(1e\)+254 more2016-05-29
CVE-2016-1409 [HIGH] CWE-20 CVE-2016-1409: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
nvd
CVE-2018-0301P2CRITICALCVSS 9.8≥ 6.0, < 7.3\(3\)n1\(1\)≥ 7.2, < 7.3\(2\)d1\(1\)+14 more2018-06-20
CVE-2018-0301 [CRITICAL] CWE-20 CVE-2018-0301: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, causing a buffer overflow. The vulnerability is due to incorrect input validation in the authentication module of the NX-API subsystem. An attacker could exploit this vulner
nvd
CVE-2022-20650P2HIGHCVSS 8.8v10.2\(1.72\)v7.3\(8\)n1\(0.4\)2022-02-23
CVE-2022-20650 [HIGH] CWE-78 CVE-2022-20650: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to
nvd
CVE-2019-1614P2HIGHCVSS 8.8≥ 8.2, < 8.3\(2\)≥ 7.3, < 8.1\(1b\)+8 more2019-03-11
CVE-2019-1614 [HIGH] CWE-77 CVE-2019-1614: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the
nvd
CVE-2016-1453P2CRITICALCVSS 9.8v4.1.\(2\)v4.1.\(3\)+44 more2016-10-06
CVE-2016-1453 [CRITICAL] CWE-119 CVE-2016-1453: Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through
Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.
nvd
CVE-2021-1361P2CRITICALCVSS 9.1v9.3\(5\)v9.3\(6\)2021-02-24
CVE-2021-1361 [CRITICAL] CWE-552 CVE-2021-1361: A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Se
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenticated, remote attacker to create, delete, or overwrite arbitrary files with root privileges on the device. This
nvd
CVE-2018-0313P2HIGHCVSS 8.8v7.0\(0\)hsk\(0.357\)v8.0\(1\)s20+3 more2018-06-21
CVE-2018-0313 [HIGH] CWE-20 CVE-2018-0313: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerability is due to incorrect input validation of user-supplied data to the NX-API subsystem. An attacker could exploit th
nvd
CVE-2019-1599P3HIGHCVSS 8.6≥ 9.2, < 9.2\(2\)≥ 7.0\(3\), < 7.0\(3\)i7\(5\)+14 more2019-03-07
CVE-2019-1599 [HIGH] CWE-399 CVE-2019-1599: A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could exploit this vulnerability by sending crafted TCP streams
nvd
CVE-2018-0293P2HIGHCVSS 8.8≥ 6.0, < 7.3\(3\)n1\(1\)v7.3\(2\)n1\(0.395\)+4 more2018-06-20
CVE-2018-0293 [HIGH] CWE-264 CVE-2018-0293: A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenti
A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess valid user credentials for the device. The vulnerability is due to incorrect RBAC privilege assignment for certain CL
nvd
CVE-2018-0310P3CRITICALCVSS 9.8v7.0\(0\)hsk\(0.357\)v8.1\(0.2\)s0+7 more2018-06-21
CVE-2018-0310 [CRITICAL] CWE-399 CVE-2018-0310: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive information from memory or cause a denial of service (DoS) condition on the affected product. The vulnerability exists because the affected software insufficiently validates header
nvd
CVE-2020-3119P3HIGHCVSS 8.8≥ 7.0\(3\)f2, < 9.3\(2\)≥ 7.0\(3\)i, < 7.0\(3\)i7\(8\)+3 more2020-02-05
CVE-2020-3119 [HIGH] CWE-787 CVE-2020-3119: A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow
A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol
nvd
CVE-2018-0330P3HIGHCVSS 8.8≥ 7.3, < 7.3\(3\)n1\(1\)v6.0+13 more2018-06-20
CVE-2018-0330 [HIGH] CWE-264 CVE-2018-0330: A vulnerability in the NX-API management application programming interface (API) in devices running,
A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a failure to properly validate certain parameters included within an NX-API request. An attacker tha
nvd
CVE-2020-3172P3HIGHCVSS 8.8v5.2\(1\)sv5\(1.2\)v7.3\(5\)n1\(1\)+5 more2020-02-26
CVE-2020-3172 [HIGH] CWE-20 CVE-2020-3172: A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Softw
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers
nvd
CVE-2013-1179P3CRITICALCVSS 9.0v4.0v4.0\(0\)n1\(1a\)+69 more2013-04-25
CVE-2013-1179 [CRITICAL] CWE-119 CVE-2013-1179: Multiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on
Multiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allow remote authenticated users to execute arbitrary code via a crafted SNMP request, aka Bug ID CSCtx54830.
nvd
CVE-2022-20624P3HIGHCVSS 7.5v7.0\(3\)v9.2\(2\)+4 more2022-02-23
CVE-2022-20624 [HIGH] CWE-400 CVE-2022-20624: A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could
A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming CFSoIP packets. An attacker could exploit this vulnerability by sending crafted
nvd
CVE-2017-3883P3HIGHCVSS 8.6v5.2v6.2+16 more2017-10-19
CVE-2017-3883 [HIGH] CWE-770 CVE-2017-3883: A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco F
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving kee
nvd
CVE-2018-0292P3HIGHCVSS 8.8≥ 6.0, < 7.3\(3\)n1\(1\)≥ 6.2, < 8.1\(2\)+3 more2018-06-20
CVE-2018-0292 [HIGH] CWE-119 CVE-2018-0292: A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Sof
A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability
nvd
CVE-2020-3415P3HIGHCVSS 8.8≥ 4.0, < 4.0\(4h\)2020-08-27
CVE-2020-3415 [HIGH] CWE-787 CVE-2020-3415: A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthent
A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability
nvd
1 / 12Next →