Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 4 of 12
CVE-2018-0090P3HIGHCVSS 7.5v7.3\(2\)n1\(0.6\)v8.3\(0\)kms\(0.31\)+1 more2018-01-18
CVE-2018-0090 [HIGH] CWE-20 CVE-2018-0090: A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS Syste
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to the NX-OS CPU for processing, leading to high CPU utilization and a denial of service (DoS) condit
nvd
CVE-2018-0295P3HIGHCVSS 7.5≥ 6.0, < 7.3\(3\)n1\(1\)≥ 6.2, < 8.1\(2\)+6 more2018-06-20
CVE-2018-0295 [HIGH] CWE-20 CVE-2018-0295: A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could al
A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the device unexpectedly reloading. The vulnerability is due to incomplete input validation of the BGP update messages. An attacker could exploit this vulnerability
nvd
CVE-2019-1962P3HIGHCVSS 7.5≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.1+10 more2019-08-28
CVE-2019-1962 [HIGH] CWE-20 CVE-2019-1962: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauth
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of TCP packets when processed by the Cisco Fabric Services over IP (CFSo
nvd
CVE-2019-1968P3HIGHCVSS 7.5v7.3v8.1+12 more2019-08-30
CVE-2019-1968 [HIGH] CWE-20 CVE-2019-1968: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request
nvd
CVE-2017-6649P3HIGHCVSS 7.8v7.1\(1\)n1\(1\)v7.1\(2\)n1\(1\)+10 more2017-05-22
CVE-2017-6649 [HIGH] CWE-20 CVE-2017-6649: A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Ser
A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command argum
nvd
CVE-2017-6650P3HIGHCVSS 7.8v7.1\(1\)n1\(1\)v7.1\(2\)n1\(1\)+10 more2017-05-22
CVE-2017-6650 [HIGH] CWE-20 CVE-2017-6650: A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on
A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted
nvd
CVE-2018-0307P3HIGHCVSS 7.8≥ 6.0, < 7.3\(3\)n1\(1\)≥ 6.2, < 8.1\(2\)+4 more2018-06-20
CVE-2018-0307 [HIGH] CWE-20 CVE-2018-0307: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to p
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI command. A
nvd
CVE-2018-0306P3HIGHCVSS 7.8fixed in 7.3\(3\)n1\(1\)v8.1\(0.2\)s0+6 more2018-06-21
CVE-2018-0306 [HIGH] CWE-20 CVE-2018-0306: A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attack
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI comm
nvd
CVE-2019-1605P3HIGHCVSS 7.8≥ 7.3, < 8.1\(1\)fixed in 6.0\(2\)a8\(8\)+6 more2019-03-08
CVE-2019-1605 [HIGH] CWE-20 CVE-2019-1605: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local at
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to incorrect input validation in the NX-API feature. An attacker could exploit this vulnerability by sending a crafted HTTP or HTTPS request to an internal service on an affected device tha
nvd
CVE-2018-0456P3HIGHCVSS 7.7v9.2\(0.43\)2018-10-17
CVE-2018-0456 [HIGH] CWE-20 CVE-2018-0456: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exp
nvd
CVE-2019-1591P3HIGHCVSS 7.8fixed in 14.0\(3d\)2019-03-06
CVE-2019-1591 [HIGH] CWE-264 CVE-2019-1591: A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insufficient sanitization of user-supplied input when issuing a specific CLI command with parameters on an affected device
nvd
CVE-2019-1966P3HIGHCVSS 7.8≤ 3.2v4.02019-08-30
CVE-2019-1966 [HIGH] CWE-264 CVE-2019-1966: A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerability is due to extraneous subcommand options present for a specific CLI command within the loca
nvd
CVE-2019-1592P3HIGHCVSS 7.8v14.1\(0.90\)2019-05-03
CVE-2019-1592 [HIGH] CWE-264 CVE-2019-1592: A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Ce
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affected device. The vulnerability is due to insufficient validation of user-supplied files on an affected device. An at
nvd
CVE-2018-0337P3HIGHCVSS 7.8v7.0\(8\)n1\(1\)v7.1\(4\)n1\(1\)+10 more2018-06-21
CVE-2018-0337 [HIGH] CWE-20 CVE-2018-0337: A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issu
nvd
CVE-2015-0718P3HIGHCVSS 7.5vbase2016-03-03
CVE-2015-0718 [HIGH] CWE-399 CVE-2015-0718: Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Comp
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.
nvd
CVE-2018-0309P3HIGHCVSS 7.7v7.0\(3\)i5\(2\)v7.0\(3\)i6\(1\)2018-06-21
CVE-2018-0309 [HIGH] CWE-400 CVE-2018-0309: A vulnerability in the implementation of a specific CLI command and the associated Simple Network Ma
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condi
nvd
CVE-2019-1967P3HIGHCVSS 7.5v6.2v7.3+18 more2019-08-30
CVE-2019-1967 [HIGH] CWE-399 CVE-2019-1967: A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an un
A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to excessive use of system resources when the affected device is logging a drop action for received MODE_PRIVATE (Mode 7) NTP packe
nvd
CVE-2019-1964P3HIGHCVSS 7.5≥ 8.1, < 8.2\(3\)≥ 8.3, < 8.42019-08-28
CVE-2019-1964 [HIGH] CWE-20 CVE-2019-1964: A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticate
A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device. The vulnerability is due to improper validation of IPv6 traffic sent through an affected device. An attacker could exploit this vulnerability by sending a malf
nvd
CVE-2018-0298P3HIGHCVSS 7.5≥ 3.0\(2\), < 3.1\(3a\)a2018-06-21
CVE-2018-0298 [HIGH] CWE-20 CVE-2018-0298: A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow a
A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP or HTTPS packet directed to
nvd
CVE-2021-1230P3HIGHCVSS 7.5v12.0\(1m\)v12.0\(1n\)+101 more2021-02-24
CVE-2021-1230 [HIGH] CWE-233 CVE-2021-1230: A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches i
A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denial of service (DoS) condition. This vulnerability is due to an issue with the installation of ro
nvd