cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 12 of 12
CVE-2021-1231P4MEDIUMCVSS 4.7v11.0\(1b\)v11.0\(1c\)+162 more2021-02-24
CVE-2021-1231 [MEDIUM] CWE-284 CVE-2021-1231: A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP p
nvd
CVE-2012-4135P4MEDIUMCVSS 4.6≤ 6.1\(2\)v4.0+96 more2013-12-21
CVE-2012-4135 [MEDIUM] CWE-22 CVE-2012-4135: Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.
nvd
CVE-2021-1583P4MEDIUMCVSS 4.4v14.2\(7f\)2021-08-25
CVE-2021-1583 [MEDIUM] CWE-284 CVE-2021-1583: A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series F A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker with Administrator privileges c
nvd
CVE-2017-12336P4MEDIUMCVSS 4.2v6.0\(2\)a8\(3\)v8.0\(1\)+4 more2017-11-30
CVE-2017-12336 [MEDIUM] CWE-20 CVE-2017-12336: A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authent A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation of user-supplied files passed to the interactive TCL
nvd
CVE-2020-3174P4MEDIUMCVSS 4.7v8.1\(1\)v8.4\(1\)+1 more2020-02-26
CVE-2020-3174 [MEDIUM] CWE-345 CVE-2020-3174: A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticate A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request.
nvd
CVE-2015-6295P4MEDIUMCVSS 4.8v6.1\(2\)i3\(4\)v7.0\(3\)i1\(1\)2015-09-20
CVE-2015-6295 [MEDIUM] CWE-399 CVE-2015-6295: Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN number, aka Bug ID CSCuw13560.
nvd
CVE-2019-1808P4MEDIUMCVSS 4.4≥ 7.3, < 8.1\(1a\)≥ 8.2, < 8.3\(1\)+2 more2019-05-15
CVE-2019-1808 [MEDIUM] CWE-347 CVE-2019-1808: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulne
nvd
CVE-2021-1367P4MEDIUMCVSS 4.3v9.3\(5\)2021-02-24
CVE-2021-1367 [MEDIUM] CWE-20 CVE-2021-1367: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could al A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an a
nvd
CVE-2019-1589P4MEDIUMCVSS 4.6v8.3\(0\)sk\(0.39\)2019-05-03
CVE-2019-1589 [MEDIUM] CWE-200 CVE-2019-1589: A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive information on an affected device. The vulnerability is due to a lack of proper data-protection
nvd
CVE-2019-1600P4MEDIUMCVSS 4.4≥ 8.2, < 8.3\(1\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(4\)+12 more2019-03-07
CVE-2019-1600 [MEDIUM] CWE-264 CVE-2019-1600: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability
nvd
CVE-2019-1731P4MEDIUMCVSS 4.4fixed in 7.0\(3\)i4\(9\)≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)+4 more2019-05-15
CVE-2019-1731 [MEDIUM] CWE-200 CVE-2019-1731: A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an a A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an authenticated, local attacker to expose a user's private SSH key to all authenticated users on the targeted device. The attacker must authenticate with valid administrator device credentials. The vulnerability is due to incomplete error handling if a spe
nvd
CVE-2015-4225P4MEDIUMCVSS 4.0v1.0\(1.110a\)v1.0\(1e\)2015-06-27
CVE-2015-4225 [MEDIUM] CWE-264 CVE-2015-4225: Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devi Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
nvd
CVE-2015-6308P4MEDIUMCVSS 4.0v6.0\(2\)u6\(0.46\)2015-10-02
CVE-2015-6308 [MEDIUM] CWE-399 CVE-2015-6308: Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of ser Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.
nvd
CVE-2017-12340P4MEDIUMCVSS 4.2v8.1\(0.70\)s02017-11-30
CVE-2017-12340 [MEDIUM] CWE-284 CVE-2017-12340: A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Ci A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The vulnerability is
nvd
CVE-2015-4277P4MEDIUMCVSS 4.9v5.1.3v5.3.02015-08-19
CVE-2015-4277 [MEDIUM] CWE-399 CVE-2015-4277: The global-configuration implementation on Cisco ASR 9000 devices with software 5.1.3 and 5.3.0 impr The global-configuration implementation on Cisco ASR 9000 devices with software 5.1.3 and 5.3.0 improperly closes vty sessions after a commit/end operation, which allows local users to cause a denial of service (tmp/*config file creation, memory consumption, and device hang) via unspecified vectors, aka Bug ID CSCut93842.
nvd
CVE-2015-6394P4MEDIUMCVSS 4.9v5.2\(9\)n1\(1\)2015-12-05
CVE-2015-6394 [MEDIUM] CWE-399 CVE-2015-6394: The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of service (device crash) via crafted USB parameters, aka Bug ID CSCus89408.
nvd
CVE-2015-4231P4LOWCVSS 3.6v6.2\(8a\)2015-07-03
CVE-2015-4231 [LOW] CWE-264 CVE-2015-4231: The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass int The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.
nvd
CVE-2014-0684P4MEDIUMCVSS 4.6v6.2\(2\)2014-05-07
CVE-2014-0684 [MEDIUM] CWE-20 CVE-2014-0684: Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafte Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
nvd
CVE-2020-3504P4LOWCVSS 3.3≥ 4.0, < 4.0\(4i\)2020-08-27
CVE-2020-3504 [LOW] CWE-664 CVE-2020-3504: A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow a A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the
nvd
Cisco NX-OS vulnerabilities | cvebase