Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 11 of 12
CVE-2015-6277P4MEDIUMCVSS 6.1v7.3\(0\)zd\(0.47\)v4.1\(2\)e1+2 more2015-09-02
CVE-2015-6277 [MEDIUM] CWE-399 CVE-2015-6277: The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexu
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process
nvd
CVE-2021-1229P4MEDIUMCVSS 5.3v5.2\(1\)sv5\(1.3a\)v8.4\(3.53\)+1 more2021-02-24
CVE-2021-1229 [MEDIUM] CWE-401 CVE-2021-1229: A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthe
A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to improper error handling when an IPv6-configured interface receives a specific type of ICMPv6 pa
nvd
CVE-2015-4237P4MEDIUMCVSS 4.6v7.2\(0\)zz\(99.3\)v7.2\(0\)zz\(99.1\)+4 more2015-07-03
CVE-2015-4237 [MEDIUM] CWE-78 CVE-2015-4237: The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
nvd
CVE-2015-4232P4MEDIUMCVSS 4.6v6.2\(10\)2015-07-03
CVE-2015-4232 [MEDIUM] CWE-264 CVE-2015-4232: Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS command
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.
nvd
CVE-2013-1122P4MEDIUMCVSS 5.0v4.0v4.0\(0\)n1\(1a\)+68 more2013-02-13
CVE-2013-1122 [MEDIUM] CWE-20 CVE-2013-1122: Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration i
Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial of service (M1-Series module reload) via crafted packets, aka Bug ID CSCud15673.
nvd
CVE-2017-12351P4MEDIUMCVSS 5.7v7.0\(3\)i7\(1\)v8.1\(0\)bd\(0.20\)2017-11-30
CVE-2017-12351 [MEDIUM] CWE-264 CVE-2017-12351: A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticat
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perform this attack. The vulnerability is due to insufficient internal security measures in the guest
nvd
CVE-2015-4296P4MEDIUMCVSS 5.0v6.0\(2\)a6\(1\)2015-08-19
CVE-2015-4296 [MEDIUM] CWE-399 CVE-2015-4296: Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attacker
Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attackers to cause a denial of service (Java process restart) via crafted connections to the Java application, aka Bug ID CSCut87006.
nvd
CVE-2022-20625P4MEDIUMCVSS 4.3v8.2\(7.34\)v5.2\(1\)sv5\(1.3b\)+3 more2022-02-23
CVE-2022-20625 [MEDIUM] CWE-399 CVE-2022-20625: A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Softw
A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisc
nvd
CVE-2012-1357P4MEDIUMCVSS 5.0v5.0v5.12012-08-06
CVE-2012-1357 [MEDIUM] CWE-119 CVE-2012-1357: The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Ne
The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Nexus 5000 series switches allows remote attackers to cause a denial of service (device reload) via IGMP packets, aka Bug ID CSCts46521.
nvd
CVE-2011-2569P4MEDIUMCVSS 6.8v4.2v5.02011-10-27
CVE-2011-2569 [MEDIUM] CWE-264 CVE-2011-2569: Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0
Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.
nvd
CVE-2017-12332P4MEDIUMCVSS 4.4v8.1\(0\)bd\(0.20\)v8.1\(1\)2017-11-30
CVE-2017-12332 [MEDIUM] CWE-434 CVE-2017-12332: A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, loca
A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch image on an affected device. The vul
nvd
CVE-2012-3051P4MEDIUMCVSS 6.1v5.2v6.12012-09-16
CVE-2012-3051 [MEDIUM] CVE-2012-3051: Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of s
Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large number of ARP packets, aka Bug ID CSCtr44822.
nvd
CVE-2018-0395P4MEDIUMCVSS 5.3v6.0\(4\)v6.1\(3\)s2+3 more2018-10-17
CVE-2018-0395 [MEDIUM] CWE-20 CVE-2018-0395: A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software a
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields
nvd
CVE-2014-3295P4MEDIUMCVSS 4.8≤ 6.2\(2a\)v4.1.\(2\)+32 more2014-06-14
CVE-2014-3295 [MEDIUM] CWE-287 CVE-2014-3295: The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authent
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
nvd
CVE-2017-6770P4MEDIUMCVSS 4.2v1.1\(0.825a\)v1.1\(1g\)+293 more2017-08-07
CVE-2017-6770 [MEDIUM] CWE-20 CVE-2017-6770: Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS
Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated, remote attacker to t
nvd
CVE-2019-1587P4MEDIUMCVSS 4.3v8.3\(0\)sk\(0.39\)2019-05-03
CVE-2019-1587 [MEDIUM] CWE-399 CVE-2019-1587: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly validate user-supplied input. An attacker could exploit this vulnerability by issuing certain
nvd
CVE-2019-1588P4MEDIUMCVSS 4.4fixed in 14.0\(1h\)2019-03-06
CVE-2019-1588 [MEDIUM] CWE-20 CVE-2019-1588: A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infras
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A suc
nvd
CVE-2013-6982P4MEDIUMCVSS 4.3≤ 6.2\(2a\)v4.0+98 more2014-01-08
CVE-2013-6982 [MEDIUM] CWE-20 CVE-2013-6982: The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction o
The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a crafted message, aka Bug ID CSCuj03174.
nvd
CVE-2015-4213P4MEDIUMCVSS 4.0v1.1\(1g\)2015-06-24
CVE-2015-4213 [MEDIUM] CWE-200 CVE-2015-4213: Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext pa
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
nvd
CVE-2013-6975P4MEDIUMCVSS 4.6≤ 6.2\(2a\)v6.0\(1\)+6 more2014-05-20
CVE-2013-6975 [MEDIUM] CWE-22 CVE-2013-6975: Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier a
Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217.
nvd