cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 6 of 12
CVE-2012-2469P3HIGHCVSS 7.8v4.2v5.0+2 more2012-08-06
CVE-2012-2469 [HIGH] CVE-2012-2469: Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) po Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) policy is configured for Reset, allows remote attackers to cause a denial of service (device reset) via a malformed Cisco Discovery Protocol (CDP) packet, aka Bug IDs CSCtk34535 and CSCtk19132.
nvd
CVE-2019-1617P3HIGHCVSS 7.4≥ 9.2, < 9.2\(2\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(5\)2019-03-11
CVE-2019-1617 [HIGH] CWE-913 CVE-2019-1617: A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol imple A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker cou
nvd
CVE-2021-34714P3HIGHCVSS 7.4≤ 8.4\(3.115\)≤ 7.0\(3\)i7\(9\)+2 more2021-09-23
CVE-2021-34714 [HIGH] CWE-20 CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IO A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An att
nvd
CVE-2023-20169P3HIGHCVSS 7.4v10.3\(2\)2023-08-23
CVE-2023-20169 [HIGH] CWE-788 CVE-2023-20169: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS So A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to r
nvd
CVE-2012-0352P3HIGHCVSS 7.8v4.0\(0\)n1\(1a\)v4.0\(0\)n1\(2\)+52 more2012-02-16
CVE-2012-0352 [HIGH] CWE-399 CVE-2012-0352: Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x before 4.2.8, 5.0.x before 5.0.5, and 5.1.x before 5.1.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (netstack process crash and device reload) via a malformed IP packet,
nvd
CVE-2018-0102P3HIGHCVSS 7.4v7.2\(1\)d\(1\)v7.2\(2\)d1\(1\)+1 more2018-01-18
CVE-2018-0102 [HIGH] CWE-399 CVE-2018-0102: A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent at A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software attempts to free the same area of memory twice. An attacker could exploit this vulnerability by sendin
nvd
CVE-2018-0291P3MEDIUMCVSS 6.5≥ 6.0, < 7.3\(3\)n1\(1\)≥ 6.2, < 8.1\(2\)+5 more2018-06-20
CVE-2018-0291 [MEDIUM] CWE-20 CVE-2018-0291: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX- A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could e
nvd
CVE-2019-1612P3MEDIUMCVSS 6.7≥ 7.0\(3\), < 7.0\(3\)i7\(6\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(6\)+3 more2019-03-11
CVE-2019-1612 [MEDIUM] CWE-77 CVE-2019-1612: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1611P3MEDIUMCVSS 6.7≥ 7.3, < 8.3\(1\)≥ 5.2, < 6.2\(25\)+11 more2019-03-11
CVE-2019-1611 [MEDIUM] CWE-77 CVE-2019-1611: A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authentica A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by i
nvd
CVE-2019-1613P3MEDIUMCVSS 6.7v7.0\(3\)f3\(3\)v7.0\(3\)i7\(2\)+3 more2019-03-11
CVE-2019-1613 [MEDIUM] CWE-77 CVE-2019-1613: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2017-12330P3MEDIUMCVSS 6.3v7.0\(0\)hsk\(0.357\)v8.1\(0\)bd\(0.20\)+1 more2017-11-30
CVE-2017-12330 [MEDIUM] CWE-77 CVE-2017-12330: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI comman
nvd
CVE-2017-12335P3MEDIUMCVSS 6.3v7.0\(0\)hsk\(0.357\)v8.1\(0\)bd\(0.20\)+1 more2017-11-30
CVE-2017-12335 [MEDIUM] CWE-77 CVE-2017-12335: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command and gain unautho
nvd
CVE-2018-0299P3MEDIUMCVSS 6.5v4.1\(2\)e1\(1r\)2018-06-21
CVE-2018-0299 [MEDIUM] CWE-20 CVE-2018-0299: A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete validation of an SNMP poll request for a specific
nvd
CVE-2019-1963P3MEDIUMCVSS 6.5≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.4+17 more2019-08-28
CVE-2019-1963 [MEDIUM] CWE-20 CVE-2019-1963: A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXO A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of Abstract Syntax Notation One (ASN.1)-encoded
nvd
CVE-2019-1768P3MEDIUMCVSS 6.7fixed in 8.3\(1\)2019-05-16
CVE-2019-1768 [MEDIUM] CWE-119 CVE-2019-1768: A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system o
nvd
CVE-2019-1767P3MEDIUMCVSS 6.7fixed in 8.3\(1\)2019-05-15
CVE-2019-1767 [MEDIUM] CWE-119 CVE-2019-1767: A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This could allow the attacker to execute arbitrary commands with elevated privileges on the underlying operating system o
nvd
CVE-2019-1609P3MEDIUMCVSS 6.7≥ 8.2, < 8.3\(2\)≥ 7.0\(3\), < 7.0\(3\)i7\(6\)+10 more2019-03-08
CVE-2019-1609 [MEDIUM] CWE-77 CVE-2019-1609: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2017-12341P3MEDIUMCVSS 6.7v8.1\(0.59\)s0v8.1\(1\)2017-11-30
CVE-2017-12341 [MEDIUM] CWE-77 CVE-2017-12341: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software patch. An attacker could exploit t
nvd
CVE-2019-1784P3MEDIUMCVSS 6.7fixed in 7.3\(5\)n1\(1\)≥ 7.2, < 7.3\(3\)d1\(1\)+3 more2019-05-15
CVE-2019-1784 [MEDIUM] CWE-77 CVE-2019-1784: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this
nvd
CVE-2019-1778P3MEDIUMCVSS 6.7fixed in 7.0\(3\)i4\(9\)≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)+1 more2019-05-15
CVE-2019-1778 [MEDIUM] CWE-78 CVE-2019-1778: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this
nvd
Cisco NX-OS vulnerabilities | cvebase