cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 3 of 12
CVE-2021-1523P3HIGHCVSS 8.6v13.2\(3n\)v14.2\(4i\)2021-08-25
CVE-2021-1523 [HIGH] CWE-772 CVE-2021-1523: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control plane traffic to the device being dropped. This could result in one or more leaf switches being removed from the fabric
nvd
CVE-2019-1590P3HIGHCVSS 8.1v8.3\(0\)sk\(0.39\)v14.1\(0.90\)2019-05-03
CVE-2019-1590 [HIGH] CWE-295 CVE-2019-1590: A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to perform insecure TLS client authentication on an affected device. The vulnerability is due to insufficient TLS client certifi
nvd
CVE-2014-3261P3HIGHCVSS 7.6v5.2v5.2\(1\)+45 more2014-05-26
CVE-2014-3261 [HIGH] CWE-119 CVE-2014-3261: Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisc Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and
nvd
CVE-2016-1341P3CRITICALCVSS 9.8v7.0\(1\)n1\(1\)v7.0\(1\)n1\(3\)+1 more2016-02-24
CVE-2016-1341 [CRITICAL] CWE-255 CVE-2016-1341: Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a bl Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.
nvd
CVE-2023-20185P3HIGHCVSS 7.4v14.0\(1h\)v14.0\(2c\)+74 more2023-07-12
CVE-2023-20185 [HIGH] CWE-330 CVE-2023-20185: A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series F A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on af
nvd
CVE-2015-4235P3CRITICALCVSS 9.0v11.0\(1b\)v11.0\(1c\)+9 more2015-07-24
CVE-2015-4235 [CRITICAL] CWE-264 CVE-2015-4235: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the AP
nvd
CVE-2019-1858P3HIGHCVSS 8.6fixed in 8.1\(1\)fixed in 7.0\(3\)i4\(8\)+11 more2019-05-16
CVE-2019-1858 [HIGH] CWE-20 CVE-2019-1858: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXO A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly. The vulnerability is due to improper error handling when
nvd
CVE-2019-1598P3HIGHCVSS 7.5≥ 7.3, < 8.2\(1\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(1\)+8 more2019-03-07
CVE-2019-1598 [HIGH] CWE-20 CVE-2019-1598: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2019-1597P3HIGHCVSS 7.5fixed in 8.2\(1\)fixed in 7.0\(3\)i7\(1\)+4 more2019-03-07
CVE-2019-1597 [HIGH] CWE-20 CVE-2019-1597: Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) f Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP pack
nvd
CVE-2019-1616P3HIGHCVSS 7.5≥ 8.2, < 8.3\(1\)≥ 7.0\(3\), < 7.0\(3\)i7\(4\)+15 more2019-03-11
CVE-2019-1616 [HIGH] CWE-20 CVE-2019-1616: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauth A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted
nvd
CVE-2021-1227P3HIGHCVSS 8.1v8.4\(2a\)v8.4\(3\)+3 more2021-02-24
CVE-2021-1227 [HIGH] CWE-352 CVE-2021-1227: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of th
nvd
CVE-2023-20050P3HIGHCVSS 7.8fixed in 8.2\(9\)fixed in 9.3\(10\)+1 more2023-02-23
CVE-2023-20050 [HIGH] CWE-78 CVE-2023-20050: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including craf
nvd
CVE-2020-10136P3MEDIUMCVSS 5.3v5.2\(1\)sk3\(1.1\)v5.2\(1\)sk3\(2.1\)+251 more2020-06-02
CVE-2020-10136 [MEDIUM] CWE-290 CVE-2020-10136: IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate a IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
nvd
CVE-2015-0721P3HIGHCVSS 8.0v4.1.\(2\)v4.1.\(3\)+176 more2016-10-06
CVE-2015-0721 [HIGH] CWE-264 CVE-2015-0721: Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 55 Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, an
nvd
CVE-2013-1178P3HIGHCVSS 8.3v4.0v4.0\(0\)n1\(1a\)+69 more2013-04-25
CVE-2013-1178 [HIGH] CWE-119 CVE-2013-1178: Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nex Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1),
nvd
CVE-2018-0311P3HIGHCVSS 7.5v7.0\(0\)hsk\(0.357\)v8.1\(0.2\)s0+8 more2018-06-21
CVE-2018-0311 [HIGH] CWE-399 CVE-2018-0311: A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Softwa A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packets when the software processe
nvd
CVE-2018-0090P3HIGHCVSS 7.5v7.3\(2\)n1\(0.6\)v8.3\(0\)kms\(0.31\)+1 more2018-01-18
CVE-2018-0090 [HIGH] CWE-20 CVE-2018-0090: A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS Syste A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to the NX-OS CPU for processing, leading to high CPU utilization and a denial of service (DoS) condit
nvd
CVE-2015-0658P3HIGHCVSS 7.9v6.1\(2\)v6.1\(3\)+66 more2015-03-28
CVE-2015-0658 [HIGH] CWE-20 CVE-2015-0658: The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not prop The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
nvd
CVE-2019-1605P3HIGHCVSS 7.8≥ 7.3, < 8.1\(1\)fixed in 6.0\(2\)a8\(8\)+6 more2019-03-08
CVE-2019-1605 [HIGH] CWE-20 CVE-2019-1605: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local at A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to incorrect input validation in the NX-API feature. An attacker could exploit this vulnerability by sending a crafted HTTP or HTTPS request to an internal service on an affected device tha
nvd
CVE-2019-1735P3HIGHCVSS 7.8fixed in 8.3\(1\)fixed in 7.0\(3\)i7\(6\)+11 more2019-05-15
CVE-2019-1735 [HIGH] CWE-77 CVE-2019-1735: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by in
nvd
Cisco NX-OS vulnerabilities | cvebase