Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 10 of 12
CVE-2011-2581P4MEDIUMCVSS 5.0v5.0\(2\)v5.0\(3\)n1\(1\)+8 more2011-09-14
CVE-2011-2581 [MEDIUM] CWE-264 CVE-2011-2581: The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series swit
The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending pack
nvd
CVE-2013-5566P4MEDIUMCVSS 5.0≤ 5.0v4.0+36 more2013-11-08
CVE-2013-5566 [MEDIUM] CWE-119 CVE-2013-5566: Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.
nvd
CVE-2015-0686P4MEDIUMCVSS 6.3v6.1\(2\)i2\(3\)2015-04-03
CVE-2015-0686 [MEDIUM] CWE-399 CVE-2015-0686: The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availabi
The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq92240.
nvd
CVE-2018-0331P4MEDIUMCVSS 6.5≥ 7.1, < 7.1\(5\)n1\(1\)≥ 7.3, < 7.3\(3\)n1\(1\)+16 more2018-06-21
CVE-2018-0331 [MEDIUM] CWE-399 CVE-2018-0331: A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Di
nvd
CVE-2015-4323P4MEDIUMCVSS 6.1v6.2\(14\)s1v6.0\(2\)u5\(1.41\)+4 more2015-08-19
CVE-2015-4323 [MEDIUM] CWE-119 CVE-2015-4323: Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.9); Nexus 3000 d
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.9); Nexus 3000 devices 6.0(2)U5(1.41), 7.0(3)I2(0.373), and 7.3(0)ZN(0.83); Nexus 4000 devices 4.1(2)E1(1b); Nexus 7000 devices 6.2(14)S1; Nexus 9000 devices 7.3(0)ZN(0.9); and MDS 9000 devices 6.2 (13) and 7.1(0)ZN(91.99) and MDS SAN-OS 7.1(0)ZN(91.99) allows remote a
nvd
CVE-2015-0775P4MEDIUMCVSS 5.0v4.1\(2\)e1\(1f\)v7.2\(0\)zn\(99.67\)+2 more2015-06-12
CVE-2015-0775 [MEDIUM] CWE-399 CVE-2015-0775: The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.
The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(0)ZN(99.67) on Nexus 3000 devices allows remote attackers to cause a denial of service (login
nvd
CVE-2017-12338P4MEDIUMCVSS 6.0v8.0\(1\)v8.1\(0\)bd\(0.20\)+1 more2017-11-30
CVE-2017-12338 [MEDIUM] CWE-20 CVE-2017-12338: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An exploit could allow the attacker
nvd
CVE-2019-1733P4MEDIUMCVSS 5.4≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)2019-05-15
CVE-2019-1733 [MEDIUM] CWE-79 CVE-2019-1733: A vulnerability in the NX API (NX-API) Sandbox interface for Cisco NX-OS Software could allow an aut
A vulnerability in the NX API (NX-API) Sandbox interface for Cisco NX-OS Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the NX-API Sandbox interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the NX-API Sandbox interface. A
nvd
CVE-2019-1734P4MEDIUMCVSS 5.5fixed in 6.2\(7\)fixed in 7.0\(3\)i4\(9\)+8 more2019-11-05
CVE-2019-1734 [MEDIUM] CWE-200 CVE-2019-1734: A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco N
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based
nvd
CVE-2017-6655P4MEDIUMCVSS 6.5v8.0\(1\)s2v8.3\(0\)cv\(0.833\)2017-06-13
CVE-2017-6655 [MEDIUM] CWE-119 CVE-2017-6655: A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Sof
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when an FCoE-related process unexpectedly reloads. This vulnerability affects Cisco NX-OS Software on the following Cisco devices when they are configur
nvd
CVE-2019-1595P4MEDIUMCVSS 6.5fixed in 7.3\(5\)n1\(1\)2019-03-06
CVE-2019-1595 [MEDIUM] CWE-913 CVE-2019-1595: A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Sof
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an incorrect allocation of an internal interface index. An adjacent attacker with the ability to subm
nvd
CVE-2023-20168P4MEDIUMCVSS 6.5v9.3\(11\)v10.2\(5\)2023-08-23
CVE-2023-20168 [MEDIUM] CWE-120 CVE-2023-20168: A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An at
nvd
CVE-2015-4324P4MEDIUMCVSS 6.1v7.3\(0\)zn\(0.81\)v4.1\(2\)e1\(1c\)+1 more2015-08-19
CVE-2015-4324 [MEDIUM] CWE-119 CVE-2015-4324: Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled
nvd
CVE-2017-3804P4MEDIUMCVSS 6.1v7.1\(3\)n1\(2.1\)v7.1\(3\)n1\(3.12\)+2 more2017-01-26
CVE-2017-3804 [MEDIUM] CVE-2017-3804: A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of
A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of Cisco Nexus 5000, 6000, and 7000 Series Switches software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device. Switches in the FabricPath domain crash because of an __inst_001__isis_fabricpath hap reset when processing a cr
nvd
CVE-2019-1729P4MEDIUMCVSS 6.0fixed in 7.0\(3\)i4\(9\)≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)+1 more2019-05-15
CVE-2019-1729 [MEDIUM] CWE-20 CVE-2019-1729: A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco
A vulnerability in the CLI implementation of a specific command used for image maintenance for Cisco NX-OS Software could allow an authenticated, local attacker to overwrite any file on the file system including system files. These file overwrites by the attacker are accomplished at the root privilege level. The vulnerability occurs because there is no
nvd
CVE-2016-1465P4MEDIUMCVSS 6.5v4.0\(4\)sv1\(1\)v4.0\(4\)sv1\(2\)+19 more2016-07-28
CVE-2016-1465 [MEDIUM] CWE-399 CVE-2016-1465: Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attac
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.
nvd
CVE-2016-6457P4MEDIUMCVSS 6.5v11.2\(2g\)v11.2\(2h\)+13 more2016-11-19
CVE-2016-6457 [MEDIUM] CWE-119 CVE-2016-6457: A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infras
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastr
nvd
CVE-2024-20294P4MEDIUMCVSS 6.6v12.0\(1m\)v12.0\(1n\)+456 more2024-02-29
CVE-2024-20294 [MEDIUM] CWE-805 CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vu
nvd
CVE-2023-20089P4MEDIUMCVSS 6.5v15.2\(1g\)v15.2\(2e\)+14 more2023-02-23
CVE-2023-20089 [MEDIUM] CWE-789 CVE-2023-20089: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabr
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due to incorrect error checking when
nvd
CVE-2015-4197P4MEDIUMCVSS 6.1v5.2\(5\)2015-06-20
CVE-2015-4197 [MEDIUM] CWE-20 CVE-2015-4197: Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (devic
Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415.
nvd