cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 2 of 12
CVE-2021-1368P3HIGHCVSS 8.8v8.4\(3.108\)v8.4\(3.117\)+5 more2021-02-24
CVE-2021-1368 [HIGH] CWE-787 CVE-2021-1368: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An a
nvd
CVE-2013-1180P3CRITICALCVSS 9.0v4.0v4.0\(0\)n1\(1a\)+69 more2013-04-25
CVE-2013-1180 [CRITICAL] CWE-119 CVE-2013-1180: Buffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5 Buffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allows remote authenticated users to execute arbitrary code via a crafted SNMP request, aka Bug ID CSCtx54822.
nvd
CVE-2021-1586P3HIGHCVSS 8.6v15.0\(2e\)v15.1\(1h\)2021-08-25
CVE-2021-1586 [HIGH] CWE-345 CVE-2021-1586: A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fa A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in a denial of service (DoS) condition. This vulnerability exists because TCP traffic sent to a sp
nvd
CVE-2020-3217P3HIGHCVSS 8.8v6.0\(2\)av6.0\(2\)a4\(1\)+192 more2020-06-03
CVE-2020-3217 [HIGH] CWE-20 CVE-2020-3217: A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Sof A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff
nvd
CVE-2018-0303P3HIGHCVSS 8.8v7.0\(0\)hsk\(0.357\)v8.1\(0.2\)s0+6 more2018-06-21
CVE-2018-0303 [HIGH] CWE-20 CVE-2018-0303: A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Sof A vulnerability in the Cisco Discovery Protocol component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on the affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet head
nvd
CVE-2024-20284P3HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20284 [HIGH] CWE-693 CVE-2024-20284: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2024-20286P3HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20286 [HIGH] CWE-693 CVE-2024-20286: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2024-20285P3HIGHCVSS 8.8v9.3\(13\)2024-08-28
CVE-2024-20285 [HIGH] CWE-653 CVE-2024-20285: A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low- A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerabil
nvd
CVE-2018-0378P3HIGHCVSS 8.6v7.3\(2\)n1\(0.8\)2018-10-17
CVE-2018-0378 [HIGH] CWE-20 CVE-2018-0378: A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Ser A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of protection against PTP frame flood attacks. An attacker coul
nvd
CVE-2022-20623P3HIGHCVSS 7.5≥ 7.0\(3\)i6\(2\), ≤ 7.0\(3\)i7\(3\)≥ 7.0\(3\)i6\(2\), ≤ 9.3\(8\)+1 more2022-02-23
CVE-2022-20623 [HIGH] CWE-399 CVE-2022-20623: A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker cou
nvd
CVE-2019-1901P3HIGHCVSS 8.8fixed in 13.2\(7f\)≥ 14.0\(1h\), ≤ 14.1\(2g\)2019-07-31
CVE-2019-1901 [HIGH] CWE-119 CVE-2019-1901: A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series App A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation
nvd
CVE-2024-20267P3HIGHCVSS 8.6v6.0\(2\)a3\(1\)v6.0\(2\)a3\(2\)+203 more2024-02-29
CVE-2024-20267 [HIGH] CWE-120 CVE-2024-20267: A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenti A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload. This vulnerability is due to lack of proper error checking when processing an ingress MPLS frame.
nvd
CVE-2020-3165P3HIGHCVSS 8.2v9.2\(1\)v9.2\(2\)+2 more2020-02-26
CVE-2020-3165 [HIGH] CWE-798 CVE-2020-3165: A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authen A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability occurs because the BGP MD5 authentication is bypassed if the peer does not have
nvd
CVE-2016-1302P3HIGHCVSS 8.8vbase2016-02-07
CVE-2016-1302 [HIGH] CWE-284 CVE-2016-1302: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.
nvd
CVE-2020-3228P3HIGHCVSS 8.6v5.2\(1\)sv3\(3.1\)v5.2\(1\)sv3\(3.15\)+7 more2020-06-03
CVE-2020-3228 [HIGH] CWE-20 CVE-2020-3228: A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE So A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because crafted SXP packets are mishandled. An attacker coul
nvd
CVE-2021-1387P3HIGHCVSS 8.6v7.0\(0\)n1\(1\)v7.0\(1\)n1\(1\)+237 more2021-02-24
CVE-2021-1387 [HIGH] CWE-401 CVE-2021-1387: A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because the software improperly releases resources when it processes certain IPv6 packets that are destined to an affected device. An attacker could expl
nvd
CVE-2021-1588P3HIGHCVSS 8.6v7.0\(3\)i7\(9\)v8.4\(1\)+1 more2021-08-25
CVE-2021-1588 [HIGH] CWE-126 CVE-2021-1588: A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply pac
nvd
CVE-2024-20321P3HIGHCVSS 8.6v7.0\(3\)f1\(1\)v7.0\(3\)f2\(1\)+46 more2024-02-29
CVE-2024-20321 [HIGH] CWE-400 CVE-2024-20321: A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Softwar A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulner
nvd
CVE-2020-3175P3HIGHCVSS 8.6v6.2\(1\)2020-02-26
CVE-2020-3175 [HIGH] CWE-664 CVE-2020-3175: A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Mu A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource usage control. An attacker could exploit this vulnerability by sending traf
nvd
CVE-2020-3517P3HIGHCVSS 8.6v6.0\(2\)a3\(1\)v6.0\(2\)a3\(2\)+284 more2020-08-27
CVE-2020-3517 [HIGH] CWE-476 CVE-2020-3517: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. For more information about
nvd