cbcvebase.

Cisco NX-OS vulnerabilities

239 known vulnerabilities affecting cisco/nx-os.

Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2

Vulnerabilities

Page 7 of 12
CVE-2019-1776P3MEDIUMCVSS 6.7fixed in 8.2\(2\)≥ 8.3, < 8.3\(1\)+9 more2019-05-15
CVE-2019-1776 [MEDIUM] CWE-78 CVE-2019-1776: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vu
nvd
CVE-2019-1795P3MEDIUMCVSS 6.7fixed in 8.2\(3\)≥ 8.3, < 8.3\(1\)+13 more2019-05-15
CVE-2019-1795 [MEDIUM] CWE-77 CVE-2019-1795: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An atta
nvd
CVE-2019-1780P3MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.1\(1b\)+11 more2019-05-16
CVE-2019-1780 [MEDIUM] CWE-77 CVE-2019-1780: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI com
nvd
CVE-2019-1610P3MEDIUMCVSS 6.7≥ 7.0\(3\), ≤ 7.0\(3\)i7\(4\)fixed in 7.0\(3\)i7\(4\)2019-03-11
CVE-2019-1610 [MEDIUM] CWE-77 CVE-2019-1610: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1608P3MEDIUMCVSS 6.7≥ 8.2, < 8.3\(1\)≥ 7.3, < 8.1\(1b\)+4 more2019-03-08
CVE-2019-1608 [MEDIUM] CWE-77 CVE-2019-1608: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2019-1607P3MEDIUMCVSS 6.7≥ 8.0, < 8.2\(3\)≥ 7.2, < 7.3\(3\)d1\(1\)+1 more2019-03-08
CVE-2019-1607 [MEDIUM] CWE-77 CVE-2019-1607: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input
nvd
CVE-2017-12329P3MEDIUMCVSS 6.3v5.2\(1\)sv3\(2.8\)v8.0\(1\)+2 more2017-11-30
CVE-2017-12329 [MEDIUM] CWE-77 CVE-2017-12329: A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System So A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting craft
nvd
CVE-2014-2201P3HIGHCVSS 7.8v6.0\(1\)≤ 6.2\(5a\)+5 more2014-05-26
CVE-2014-2201 [HIGH] CVE-2014-2201: The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6 The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915.
nvd
CVE-2024-20291P3MEDIUMCVSS 5.8v9.3\(10\)v9.3\(11\)+1 more2024-02-29
CVE-2024-20291 [MEDIUM] CWE-284 CVE-2024-20291: A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs wh
nvd
CVE-2013-1191P3HIGHCVSS 7.1v6.1v6.1\(1\)+4 more2014-05-26
CVE-2013-1191 [HIGH] CWE-264 CVE-2013-1191: Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
nvd
CVE-2014-2200P4HIGHCVSS 7.1v5.0\(3\)n1\(1\)v5.0\(3\)n1\(1a\)+28 more2014-05-26
CVE-2014-2200 [HIGH] CWE-264 CVE-2014-2200: Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629.
nvd
CVE-2017-12334P4MEDIUMCVSS 6.7v6.0\(2\)a8\(3\)v7.0\(0\)hsk\(0.357\)+3 more2017-11-30
CVE-2017-12334 [MEDIUM] CWE-20 CVE-2017-12334: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by in
nvd
CVE-2019-1791P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.2\(3\)+10 more2019-05-15
CVE-2019-1791 [MEDIUM] CWE-77 CVE-2019-1791: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could
nvd
CVE-2019-1783P3MEDIUMCVSS 6.7fixed in 7.3\(4\)n1\(1\)≥ 7.2, < 7.3\(3\)d1\(1\)+1 more2019-05-15
CVE-2019-1783 [MEDIUM] CWE-77 CVE-2019-1783: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device.
nvd
CVE-2019-1769P4MEDIUMCVSS 6.7fixed in 7.0\(3\)i7\(6\)≥ 7.0\(3\), < 7.0\(3\)f3\(5\)2019-05-15
CVE-2019-1769 [MEDIUM] CWE-78 CVE-2019-1769: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system of an attached line card with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command
nvd
CVE-2019-1790P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.1\(1b\)+10 more2019-05-15
CVE-2019-1790 [MEDIUM] CWE-77 CVE-2019-1790: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with valid administrator credentials to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulne
nvd
CVE-2019-1782P4MEDIUMCVSS 6.7fixed in 4.0\(1a\)≥ 5.2, < 6.2\(25\)+11 more2019-05-15
CVE-2019-1782 [MEDIUM] CWE-77 CVE-2019-1782: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by
nvd
CVE-2019-1775P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.1\(1b\)+10 more2019-05-15
CVE-2019-1775 [MEDIUM] CWE-78 CVE-2019-1775: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious inpu
nvd
CVE-2019-1781P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.3\(2\)+11 more2019-05-15
CVE-2019-1781 [MEDIUM] CWE-77 CVE-2019-1781: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by
nvd
CVE-2019-1774P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.1\(1b\)+10 more2019-05-15
CVE-2019-1774 [MEDIUM] CWE-78 CVE-2019-1774: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to e A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious inpu
nvd
Cisco NX-OS vulnerabilities | cvebase