Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 8 of 12
CVE-2019-1779P4MEDIUMCVSS 6.7≥ 5.2, < 6.2\(25\)≥ 7.3, < 8.1\(1b\)+8 more2019-05-15
CVE-2019-1779 [MEDIUM] CWE-77 CVE-2019-1779: A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authentica
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploi
nvd
CVE-2019-1728P4MEDIUMCVSS 6.7≥ 8.1, < 8.1\(1b\)≥ 8.2, < 8.3\(1\)+9 more2019-05-15
CVE-2019-1728 [MEDIUM] CWE-347 CVE-2019-1728: A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisc
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration informatio
nvd
CVE-2019-1727P4MEDIUMCVSS 6.7≥ 5.2, < 8.1\(1b\)≥ 8.2, < 8.3\(1\)+5 more2019-05-15
CVE-2019-1727 [MEDIUM] CWE-264 CVE-2019-1727: A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticat
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions in the s
nvd
CVE-2017-3875P4MEDIUMCVSS 5.3v5.2\(4\)v6.1\(3\)s5+5 more2017-03-17
CVE-2017-3875 [MEDIUM] CWE-20 CVE-2017-3875: An Access-Control Filtering Mechanisms Bypass vulnerability in certain access-control filtering mech
An Access-Control Filtering Mechanisms Bypass vulnerability in certain access-control filtering mechanisms on Cisco Nexus 7000 Series Switches could allow an unauthenticated, remote attacker to bypass defined traffic configured within an access control list (ACL) on the affected system. More Information: CSCtz59354. Known Affected Releases: 5.2(4) 6.1(
nvd
CVE-2019-1649P4MEDIUMCVSS 6.7fixed in 8.4.1fixed in 9.3\(2\)2019-05-13
CVE-2019-1649 [MEDIUM] CWE-284 CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco'
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vuln
nvd
CVE-2017-12301P4MEDIUMCVSS 6.7v7.0\(3\)i4\(6\)v8.1\(0\)bd\(0.20\)+7 more2017-10-19
CVE-2017-12301 [MEDIUM] CWE-20 CVE-2017-12301: A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticat
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functi
nvd
CVE-2018-0294P4MEDIUMCVSS 6.7v7.3\(2\)n1\(0.354\)v5.2\(1\)sv3\(1.10\)+3 more2018-06-20
CVE-2018-0294 [MEDIUM] CWE-264 CVE-2018-0294: A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could all
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear th
nvd
CVE-2021-1584P4MEDIUMCVSS 6.7v14.2\(7f\)2021-08-25
CVE-2021-1584 [MEDIUM] CWE-78 CVE-2021-1584: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions during the execution of a specific CLI command. An attacker with administrative privileges could expl
nvd
CVE-2019-1732P4MEDIUMCVSS 6.4≥ 7.0\(3\)i4, < 7.0\(3\)i7\(4\)2019-05-15
CVE-2019-1732 [MEDIUM] CWE-78 CVE-2019-1732: A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to arbitrary command injection. The vulnerability is due to the lack of a proper l
nvd
CVE-2011-4667P4MEDIUMCVSS 5.9v5.0\(5\)2017-09-25
CVE-2011-4667 [MEDIUM] CWE-310 CVE-2011-4667: The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco
The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice Module, and Cisco MDS 9000 Storage Services Node module before 5.2(6), and Cisco IOS in Cisco VPN Services Port Adaptor for Catalyst 6500 12.2(33)SXI, and 12.2(33)SXJ when IP
nvd
CVE-2020-3170P4MEDIUMCVSS 5.3fixed in 8.4\(1\)fixed in 8.2\(5\)2020-02-26
CVE-2020-3170 [MEDIUM] CWE-20 CVE-2020-3170: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP reque
nvd
CVE-2023-20115P4MEDIUMCVSS 5.4v9.2\(1\)v9.2\(2\)+28 more2023-08-23
CVE-2023-20115 [MEDIUM] CWE-671 CVE-2023-20115: A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Seri
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device.
This vulnerability is due to a logic error when verifying the user role when
nvd
CVE-2018-0092P4HIGHCVSS 7.1v7.0\(3\)i5\(2\)v7.0\(3\)i6\(1\)+1 more2018-01-18
CVE-2018-0092 [HIGH] CWE-264 CVE-2018-0092: A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software cou
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to improperly delete valid user accounts. The network-operator role should not be able to delete other configured users on the device. The vulnerability is due to a lack of proper role-based access control (RBAC)
nvd
CVE-2014-3341P4MEDIUMCVSS 5.0≤ 7.0\(3\)n1\(1\)v5.0\(2\)n1\(1\)+36 more2014-08-19
CVE-2014-3341 [MEDIUM] CWE-200 CVE-2014-3341: The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides diffe
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
nvd
CVE-2019-1730P4MEDIUMCVSS 6.7≥ 7.0\(3\)i4, < 7.0\(3\)i4\(9\)≥ 7.0\(3\)i7, < 7.0\(3\)i7\(4\)+2 more2019-05-15
CVE-2019-1730 [MEDIUM] CWE-264 CVE-2019-1730: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticat
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to bypass the limited command set of the restricted Guest Shell and execute commands at the privilege level of a network-admin user outside of the Guest Shell. The attacker must authenticate with valid administrator device credentials
nvd
CVE-2019-1810P4MEDIUMCVSS 6.7≥ 6.1\(2\)i3\(4\), < 7.0\(3\)i7\(5\)≥ 7.0\(3\)i7\(5a\), < 9.2\(2\)+4 more2019-05-15
CVE-2019-1810 [MEDIUM] CWE-347 CVE-2019-1810: A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Ne
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not
nvd
CVE-2019-1615P4MEDIUMCVSS 6.7v7.0\(3\)i7\(3\)v9.2\(1\)+2 more2019-03-11
CVE-2019-1615 [MEDIUM] CWE-347 CVE-2019-1615: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability is due to improper verification of digital signatures for software images. An attacker could exploit this vu
nvd
CVE-2021-1228P4MEDIUMCVSS 6.5v11.0\(1b\)v11.0\(1c\)+160 more2021-02-24
CVE-2021-1228 [MEDIUM] CWE-284 CVE-2021-1228: A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Serie
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. This vulnerability is due to insufficient
nvd
CVE-2017-3879P4MEDIUMCVSS 5.3v7.0\(3\)i3\(0.170\)v8.3\(0\)cv\(0.342\)+1 more2017-03-17
CVE-2017-3879 [MEDIUM] CWE-119 CVE-2017-3879: A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running
A Denial of Service vulnerability in the remote login functionality for Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. The attacker c
nvd
CVE-2017-3878P4MEDIUMCVSS 5.3v7.0\(3\)i3\(0.170\)2017-03-17
CVE-2017-3878 [MEDIUM] CWE-119 CVE-2017-3878: A Denial of Service vulnerability in the Telnet remote login functionality of Cisco NX-OS Software r
A Denial of Service vulnerability in the Telnet remote login functionality of Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause a Telnet process used for login to terminate unexpectedly and the login attempt to fail. There is no impact to user traffic flowing through the device. A
nvd