cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 5 of 12
CVE-2018-0298P3HIGHCVSS 7.5≥ 3.0\(2\), < 3.1\(3a\)a2018-06-21
CVE-2018-0298 [HIGH] CWE-20 CVE-2018-0298: A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow a A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fabric Interconnect Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to incorrect input validation in the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP or HTTPS packet directed to
nvd
CVE-2019-1977P3HIGHCVSS 7.5v12.3\(1h\)v13.1\(2m\)+2 more2019-08-30
CVE-2019-1977 [HIGH] CWE-371 CVE-2019-1977: A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets a
nvd
CVE-2018-0302P3HIGHCVSS 7.8v3.1\(1k\)a2018-06-21
CVE-2018-0302 [HIGH] CWE-20 CVE-2018-0302: A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length
nvd
CVE-2019-1604P3HIGHCVSS 7.8fixed in 7.0\(3\)i7\(4\)fixed in 7.0\(3\)f3\(5\)+3 more2019-03-08
CVE-2019-1604 [HIGH] CWE-285 CVE-2019-1604: A vulnerability in the user account management interface of Cisco NX-OS Software could allow an auth A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to an incorrect authorization check of user accounts and their associated Group ID (GID). An attacker could exploit this vulnerability by taking advantag
nvd
CVE-2019-1726P3HIGHCVSS 7.8≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.3\(2\)+8 more2019-05-15
CVE-2019-1726 [HIGH] CWE-20 CVE-2019-1726: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to a A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicio
nvd
CVE-2019-1602P3HIGHCVSS 7.8≥ 7.0\(3\)i5, < 7.0\(3\)i7\(4\)≥ 7.0\(3\)f3, < 7.0\(3\)f3\(5\)+2 more2019-03-08
CVE-2019-1602 [HIGH] CWE-264 CVE-2019-1602: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator. The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of
nvd
CVE-2019-1596P3HIGHCVSS 7.8fixed in 7.0\(3\)i4\(9\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(4\)+2 more2019-03-07
CVE-2019-1596 [HIGH] CWE-264 CVE-2019-1596: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticat A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with valid user credentials. The vulnerability is due to incorrect permissions of a system executable. An attacker could exploit this vulnerability by authenticat
nvd
CVE-2019-1603P3HIGHCVSS 7.8fixed in 7.0\(3\)i7\(4\)fixed in 7.0\(3\)f3\(5\)2019-03-08
CVE-2019-1603 [HIGH] CWE-285 CVE-2019-1603: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to
nvd
CVE-2018-0372P3HIGHCVSS 7.5v13.0\(1k\)2018-07-18
CVE-2018-0372 [HIGH] CWE-400 CVE-2018-0372: A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application- A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denial of Service (DoS) condition on an affected system. The vulnerability is due to improper memory
nvd
CVE-2020-3168P3HIGHCVSS 7.5v5.2\(1\)sv3\(4.1a\)2020-02-26
CVE-2020-3168 [HIGH] CWE-399 CVE-2020-3168: A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware v A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The vulnerability is due to improper resource allocation during failed CLI login attem
nvd
CVE-2021-1230P3HIGHCVSS 7.5v12.0\(1m\)v12.0\(1n\)+101 more2021-02-24
CVE-2021-1230 [HIGH] CWE-233 CVE-2021-1230: A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches i A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denial of service (DoS) condition. This vulnerability is due to an issue with the installation of ro
nvd
CVE-2019-1593P3HIGHCVSS 7.8≥ 7.0\(3\)i5, < 7.0\(3\)i7\(4\)≥ 7.0\(3\)i4, < 7.0\(3\)i4\(9\)+6 more2019-03-06
CVE-2019-1593 [HIGH] CWE-264 CVE-2019-1593: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticat A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that al
nvd
CVE-2016-1455P3HIGHCVSS 7.5v7.0\(3\)v7.0\(3\)i1\(1\)+3 more2016-10-05
CVE-2016-1455 [HIGH] CWE-200 CVE-2016-1455: Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-inte Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.
nvd
CVE-2019-1585P3HIGHCVSS 7.8v8.3\(0\)sk\(0.39\)2019-03-06
CVE-2019-1585 [HIGH] CWE-16 CVE-2019-1585: A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Sw A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device. The vulnerability is due to a misconfiguration of certain sudoers files for the bashroot component on an affected device. An at
nvd
CVE-2015-6392P3HIGHCVSS 7.5v4.1.\(2\)v4.1.\(3\)+103 more2016-10-06
CVE-2015-6392 [HIGH] CWE-399 CVE-2015-6392: Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.
nvd
CVE-2019-1965P3HIGHCVSS 7.7≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.4+13 more2019-08-28
CVE-2019-1965 [HIGH] CWE-400 CVE-2019-1965: A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow a A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deplete system memory. When there is no system memory available, this can cause unexpected system be
nvd
CVE-2016-1351P3HIGHCVSS 7.5v4.1\(2\)v4.1\(3\)+40 more2016-03-26
CVE-2016-1351 [HIGH] CWE-20 CVE-2016-1351: The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 th The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.
nvd
CVE-2015-6393P3HIGHCVSS 7.5v4.2\(1\)n1\(1\)v4.2\(1\)n2\(1\)+102 more2016-10-06
CVE-2015-6393 [HIGH] CWE-399 CVE-2015-6393: Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka Bug IDs CSCuq39250, CSCus21733, CSCus21739, CSCut76171, and CSCux67182.
nvd
CVE-2019-1594P3HIGHCVSS 7.4fixed in 5.2\(1\)sv3\(1.4b\)≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)+7 more2019-03-06
CVE-2019-1594 [HIGH] CWE-264 CVE-2019-1594: A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation of Extensible Authentication Protocol over LAN (EAPOL) frames. An attacker could exploit this vulnerability by
nvd
CVE-2013-1181P3HIGHCVSS 7.8v4.0v4.0\(0\)n1\(1a\)+58 more2013-04-25
CVE-2013-1181 [HIGH] CWE-20 CVE-2013-1181: Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0( Cisco NX-OS on Nexus 5500 devices 4.x and 5.x before 5.0(3)N2(2), Nexus 3000 devices 5.x before 5.0(3)U3(2), and Unified Computing System (UCS) 6200 devices before 2.0(1w) allows remote attackers to cause a denial of service (device reload) by sending a jumbo packet to the management interface, aka Bug IDs CSCtx17544, CSCts10593, and CSCtx95389.
nvd