Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 2 of 12
CVE-2021-1588HIGHCVSS 8.6v7.0\(3\)i7\(9\)v8.4\(1\)+1 more2021-08-25
CVE-2021-1588 [HIGH] CWE-126 CVE-2021-1588: A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply pac
nvd
CVE-2021-1523HIGHCVSS 8.6v13.2\(3n\)v14.2\(4i\)2021-08-25
CVE-2021-1523 [HIGH] CWE-772 CVE-2021-1523: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control plane traffic to the device being dropped. This could result in one or more leaf switches being removed from the fabric
nvd
CVE-2021-1586HIGHCVSS 8.6v15.0\(2e\)v15.1\(1h\)2021-08-25
CVE-2021-1586 [HIGH] CWE-345 CVE-2021-1586: A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fa
A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in a denial of service (DoS) condition. This vulnerability exists because TCP traffic sent to a sp
nvd
CVE-2021-1583MEDIUMCVSS 4.4v14.2\(7f\)2021-08-25
CVE-2021-1583 [MEDIUM] CWE-284 CVE-2021-1583: A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series F
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker with Administrator privileges c
nvd
CVE-2021-1584MEDIUMCVSS 6.7v14.2\(7f\)2021-08-25
CVE-2021-1584 [MEDIUM] CWE-78 CVE-2021-1584: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during the execution of a specific CLI command. An attacker with administrative privileges could expl
nvd
CVE-2021-1591MEDIUMCVSS 5.3v9.3\(4\)2021-08-25
CVE-2021-1591 [MEDIUM] CWE-284 CVE-2021-1591: A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches coul
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of resources that occurs when applying ACLs to port channel interfaces. An att
nvd
CVE-2021-1590MEDIUMCVSS 5.3v7.0\(3\)i4\(0.116\)v7.3\(7\)n1\(1b\)2021-08-25
CVE-2021-1590 [MEDIUM] CWE-787 CVE-2021-1590: A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when a
nvd
CVE-2021-1361CRITICALCVSS 9.1v9.3\(5\)v9.3\(6\)2021-02-24
CVE-2021-1361 [CRITICAL] CWE-552 CVE-2021-1361: A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Se
A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenticated, remote attacker to create, delete, or overwrite arbitrary files with root privileges on the device. This
nvd
CVE-2021-1387HIGHCVSS 8.6v7.0\(0\)n1\(1\)v7.0\(1\)n1\(1\)+237 more2021-02-24
CVE-2021-1387 [HIGH] CWE-401 CVE-2021-1387: A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because the software improperly releases resources when it processes certain IPv6 packets that are destined to an affected device. An attacker could expl
nvd
CVE-2021-1368HIGHCVSS 8.8v8.4\(3.108\)v8.4\(3.117\)+5 more2021-02-24
CVE-2021-1368 [HIGH] CWE-787 CVE-2021-1368: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An a
nvd
CVE-2021-1227HIGHCVSS 8.1v8.4\(2a\)v8.4\(3\)+3 more2021-02-24
CVE-2021-1227 [HIGH] CWE-352 CVE-2021-1227: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of th
nvd
CVE-2021-1230HIGHCVSS 7.5v12.0\(1m\)v12.0\(1n\)+101 more2021-02-24
CVE-2021-1230 [HIGH] CWE-233 CVE-2021-1230: A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches i
A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denial of service (DoS) condition. This vulnerability is due to an issue with the installation of ro
nvd
CVE-2021-1228MEDIUMCVSS 6.5v11.0\(1b\)v11.0\(1c\)+160 more2021-02-24
CVE-2021-1228 [MEDIUM] CWE-284 CVE-2021-1228: A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Serie
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. This vulnerability is due to insufficient
nvd
CVE-2021-1231MEDIUMCVSS 4.7v11.0\(1b\)v11.0\(1c\)+162 more2021-02-24
CVE-2021-1231 [MEDIUM] CWE-284 CVE-2021-1231: A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface. This vulnerability is due to incomplete validation of the source of a received LLDP p
nvd
CVE-2021-1229MEDIUMCVSS 5.3v5.2\(1\)sv5\(1.3a\)v8.4\(3.53\)+1 more2021-02-24
CVE-2021-1229 [MEDIUM] CWE-401 CVE-2021-1229: A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthe
A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to improper error handling when an IPv6-configured interface receives a specific type of ICMPv6 pa
nvd
CVE-2021-1367MEDIUMCVSS 4.3v9.3\(5\)2021-02-24
CVE-2021-1367 [MEDIUM] CWE-20 CVE-2021-1367: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could al
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted PIM packet to an a
nvd
CVE-2020-3517HIGHCVSS 8.6v6.0\(2\)a3\(1\)v6.0\(2\)a3\(2\)+284 more2020-08-27
CVE-2020-3517 [HIGH] CWE-476 CVE-2020-3517: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. For more information about
nvd
CVE-2020-3415HIGHCVSS 8.8≥ 4.0, < 4.0\(4h\)2020-08-27
CVE-2020-3415 [HIGH] CWE-787 CVE-2020-3415: A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthent
A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability
nvd
CVE-2020-3504LOWCVSS 3.3≥ 4.0, < 4.0\(4i\)2020-08-27
CVE-2020-3504 [LOW] CWE-664 CVE-2020-3504: A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow a
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the
nvd
CVE-2020-3228HIGHCVSS 8.6v5.2\(1\)sv3\(3.1\)v5.2\(1\)sv3\(3.15\)+7 more2020-06-03
CVE-2020-3228 [HIGH] CWE-20 CVE-2020-3228: A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE So
A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because crafted SXP packets are mishandled. An attacker coul
nvd