Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 3 of 12
CVE-2020-3217HIGHCVSS 8.8v6.0\(2\)av6.0\(2\)a4\(1\)+192 more2020-06-03
CVE-2020-3217 [HIGH] CWE-20 CVE-2020-3217: A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Sof A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff
nvd
CVE-2020-10136MEDIUMCVSS 5.3v5.2\(1\)sk3\(1.1\)v5.2\(1\)sk3\(2.1\)+251 more2020-06-02
CVE-2020-10136 [MEDIUM] CWE-290 CVE-2020-10136: IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate a IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
nvd
CVE-2020-3165HIGHCVSS 8.2v9.2\(1\)v9.2\(2\)+2 more2020-02-26
CVE-2020-3165 [HIGH] CWE-798 CVE-2020-3165: A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authen A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability occurs because the BGP MD5 authentication is bypassed if the peer does not have
nvd
CVE-2020-3175HIGHCVSS 8.6v6.2\(1\)2020-02-26
CVE-2020-3175 [HIGH] CWE-664 CVE-2020-3175: A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Mu A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource usage control. An attacker could exploit this vulnerability by sending traf
nvd
CVE-2020-3172HIGHCVSS 8.8v5.2\(1\)sv5\(1.2\)v7.3\(5\)n1\(1\)+5 more2020-02-26
CVE-2020-3172 [HIGH] CWE-20 CVE-2020-3172: A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Softw A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because of insufficiently validated Cisco Discovery Protocol packet headers
nvd
CVE-2020-3168HIGHCVSS 7.5v5.2\(1\)sv3\(4.1a\)2020-02-26
CVE-2020-3168 [HIGH] CWE-399 CVE-2020-3168: A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware v A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The vulnerability is due to improper resource allocation during failed CLI login attem
nvd
CVE-2020-3174MEDIUMCVSS 4.7v8.1\(1\)v8.4\(1\)+1 more2020-02-26
CVE-2020-3174 [MEDIUM] CWE-345 CVE-2020-3174: A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticate A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addresses for the subnet. The vulnerability is due to improper validation of a received gratuitous ARP (GARP) request.
nvd
CVE-2020-3170MEDIUMCVSS 5.3fixed in 8.4\(1\)fixed in 8.2\(5\)2020-02-26
CVE-2020-3170 [MEDIUM] CWE-20 CVE-2020-3170: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP reque
nvd
CVE-2020-3119HIGHCVSS 8.8≥ 7.0\(3\)f2, < 9.3\(2\)≥ 7.0\(3\)i, < 7.0\(3\)i7\(8\)+3 more2020-02-05
CVE-2020-3119 [HIGH] CWE-787 CVE-2020-3119: A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol
nvd
CVE-2020-3120MEDIUMCVSS 6.5≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.4\(1a\)+12 more2020-02-05
CVE-2020-3120 [MEDIUM] CWE-190 CVE-2020-3120: A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software proce
nvd
CVE-2019-1734MEDIUMCVSS 5.5fixed in 6.2\(7\)fixed in 7.0\(3\)i4\(9\)+8 more2019-11-05
CVE-2019-1734 [MEDIUM] CWE-200 CVE-2019-1734: A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco N A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based
nvd
CVE-2019-12717HIGHCVSS 7.8≥ 6.0\(2\), < 7.0\(3\)i7\(6\)≥ 9.2, < 9.2\(3\)+3 more2019-09-25
CVE-2019-12717 [HIGH] CWE-78 CVE-2019-12717: A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Softwar A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges. The vulnerability is due to insufficient validation of arguments passed to a specific VMAN CLI command on an affec
nvd
CVE-2019-12662MEDIUMCVSS 6.7v8.1\(0.2\)s0v8.1\(1\)+2 more2019-09-25
CVE-2019-12662 [MEDIUM] CWE-347 CVE-2019-12662: A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, loca A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Op
nvd
CVE-2019-1977HIGHCVSS 7.5v12.3\(1h\)v13.1\(2m\)+2 more2019-08-30
CVE-2019-1977 [HIGH] CWE-371 CVE-2019-1977: A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets a
nvd
CVE-2019-1967HIGHCVSS 7.5v6.2v7.3+18 more2019-08-30
CVE-2019-1967 [HIGH] CWE-399 CVE-2019-1967: A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an un A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources when the affected device is logging a drop action for received MODE_PRIVATE (Mode 7) NTP packe
nvd
CVE-2019-1966HIGHCVSS 7.8≤ 3.2v4.02019-08-30
CVE-2019-1966 [HIGH] CWE-264 CVE-2019-1966: A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerability is due to extraneous subcommand options present for a specific CLI command within the loca
nvd
CVE-2019-1968HIGHCVSS 7.5v7.3v8.1+12 more2019-08-30
CVE-2019-1968 [HIGH] CWE-20 CVE-2019-1968: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request
nvd
CVE-2019-1969MEDIUMCVSS 5.3v7.0\(3\)i7\(3\)v9.2\(2\)+2 more2019-08-30
CVE-2019-1969 [MEDIUM] CWE-264 CVE-2019-1969: A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Contro A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic. The vulnerability is due to an incorrect length check when the con
nvd
CVE-2019-1962HIGHCVSS 7.5≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.1+10 more2019-08-28
CVE-2019-1962 [HIGH] CWE-20 CVE-2019-1962: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauth A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of TCP packets when processed by the Cisco Fabric Services over IP (CFSo
nvd
CVE-2019-1965HIGHCVSS 7.7≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.4+13 more2019-08-28
CVE-2019-1965 [HIGH] CWE-400 CVE-2019-1965: A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow a A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deplete system memory. When there is no system memory available, this can cause unexpected system be
nvd