Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 6 of 12
CVE-2019-1587MEDIUMCVSS 4.3v8.3\(0\)sk\(0.39\)2019-05-03
CVE-2019-1587 [MEDIUM] CWE-399 CVE-2019-1587: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly validate user-supplied input. An attacker could exploit this vulnerability by issuing certain
nvd
CVE-2019-1618HIGHCVSS 7.8≥ 7.0\(3\)i4, < 7.0\(3\)i7\(5\)2019-03-11
CVE-2019-1618 [HIGH] CWE-275 CVE-2019-1618: A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to an incorrect permissions setting. An attacker could exploit this vulnerability by replacing valid agent files with malicious code. A succ
nvd
CVE-2019-1616HIGHCVSS 7.5≥ 8.2, < 8.3\(1\)≥ 7.0\(3\), < 7.0\(3\)i7\(4\)+15 more2019-03-11
CVE-2019-1616 [HIGH] CWE-20 CVE-2019-1616: A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauth A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Cisco Fabric Services packets. An attacker could exploit this vulnerability by sending a crafted
nvd
CVE-2019-1614HIGHCVSS 8.8≥ 8.2, < 8.3\(2\)≥ 7.3, < 8.1\(1b\)+8 more2019-03-11
CVE-2019-1614 [HIGH] CWE-77 CVE-2019-1614: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote a A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the
nvd
CVE-2019-1617HIGHCVSS 7.4≥ 9.2, < 9.2\(2\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(5\)2019-03-11
CVE-2019-1617 [HIGH] CWE-913 CVE-2019-1617: A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol imple A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to an incorrect processing of FCoE packets when the fcoe-npv feature is uninstalled. An attacker cou
nvd
CVE-2019-1610MEDIUMCVSS 6.7≥ 7.0\(3\), ≤ 7.0\(3\)i7\(4\)fixed in 7.0\(3\)i7\(4\)2019-03-11
CVE-2019-1610 [MEDIUM] CWE-77 CVE-2019-1610: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1612MEDIUMCVSS 6.7≥ 7.0\(3\), < 7.0\(3\)i7\(6\)≥ 7.0\(3\)i5, < 7.0\(3\)i7\(6\)+3 more2019-03-11
CVE-2019-1612 [MEDIUM] CWE-77 CVE-2019-1612: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1611MEDIUMCVSS 6.7≥ 7.3, < 8.3\(1\)≥ 5.2, < 6.2\(25\)+11 more2019-03-11
CVE-2019-1611 [MEDIUM] CWE-77 CVE-2019-1611: A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authentica A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by i
nvd
CVE-2019-1613MEDIUMCVSS 6.7v7.0\(3\)f3\(3\)v7.0\(3\)i7\(2\)+3 more2019-03-11
CVE-2019-1613 [MEDIUM] CWE-77 CVE-2019-1613: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1615MEDIUMCVSS 6.7v7.0\(3\)i7\(3\)v9.2\(1\)+2 more2019-03-11
CVE-2019-1615 [MEDIUM] CWE-347 CVE-2019-1615: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability is due to improper verification of digital signatures for software images. An attacker could exploit this vu
nvd
CVE-2019-1602HIGHCVSS 7.8≥ 7.0\(3\)i5, < 7.0\(3\)i7\(4\)≥ 7.0\(3\)f3, < 7.0\(3\)f3\(5\)+2 more2019-03-08
CVE-2019-1602 [HIGH] CWE-264 CVE-2019-1602: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator. The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of
nvd
CVE-2019-1606HIGHCVSS 7.8≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)≥ 7.0\(3\), < 7.0\(3\)i7\(4\)2019-03-08
CVE-2019-1606 [HIGH] CWE-77 CVE-2019-1606: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input a
nvd
CVE-2019-1601HIGHCVSS 7.8≥ 8.2, < 8.3\(1\)≥ 7.0\(3\), < 7.0\(3\)i7\(4\)+12 more2019-03-08
CVE-2019-1601 [HIGH] CWE-284 CVE-2019-1601: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict filesystem permissions on the targeted device. An attacker could exploit this vulnerability by accessing and modifying res
nvd
CVE-2019-1605HIGHCVSS 7.8≥ 7.3, < 8.1\(1\)fixed in 6.0\(2\)a8\(8\)+6 more2019-03-08
CVE-2019-1605 [HIGH] CWE-20 CVE-2019-1605: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local at A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to incorrect input validation in the NX-API feature. An attacker could exploit this vulnerability by sending a crafted HTTP or HTTPS request to an internal service on an affected device tha
nvd
CVE-2019-1604HIGHCVSS 7.8fixed in 7.0\(3\)i7\(4\)fixed in 7.0\(3\)f3\(5\)+3 more2019-03-08
CVE-2019-1604 [HIGH] CWE-285 CVE-2019-1604: A vulnerability in the user account management interface of Cisco NX-OS Software could allow an auth A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to an incorrect authorization check of user accounts and their associated Group ID (GID). An attacker could exploit this vulnerability by taking advantag
nvd
CVE-2019-1603HIGHCVSS 7.8fixed in 7.0\(3\)i7\(4\)fixed in 7.0\(3\)f3\(5\)2019-03-08
CVE-2019-1603 [HIGH] CWE-285 CVE-2019-1603: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to
nvd
CVE-2019-1609MEDIUMCVSS 6.7≥ 8.2, < 8.3\(2\)≥ 7.0\(3\), < 7.0\(3\)i7\(6\)+10 more2019-03-08
CVE-2019-1609 [MEDIUM] CWE-77 CVE-2019-1609: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1608MEDIUMCVSS 6.7≥ 8.2, < 8.3\(1\)≥ 7.3, < 8.1\(1b\)+4 more2019-03-08
CVE-2019-1608 [MEDIUM] CWE-77 CVE-2019-1608: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1607MEDIUMCVSS 6.7≥ 8.0, < 8.2\(3\)≥ 7.2, < 7.3\(3\)d1\(1\)+1 more2019-03-08
CVE-2019-1607 [MEDIUM] CWE-77 CVE-2019-1607: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1599HIGHCVSS 8.6≥ 9.2, < 9.2\(2\)≥ 7.0\(3\), < 7.0\(3\)i7\(5\)+14 more2019-03-07
CVE-2019-1599 [HIGH] CWE-399 CVE-2019-1599: A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could exploit this vulnerability by sending crafted TCP streams
nvd