Cisco NX-OS vulnerabilities
239 known vulnerabilities affecting cisco/nx-os.
Total CVEs
239
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH104MEDIUM125LOW2
Vulnerabilities
Page 9 of 12
CVE-2009-0627P4HIGHCVSS 7.8≤ 4.02009-09-08
CVE-2009-0627 [HIGH] CVE-2009-0627: Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms,
Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.
nvd
CVE-2019-1969P4MEDIUMCVSS 5.3v7.0\(3\)i7\(3\)v9.2\(2\)+2 more2019-08-30
CVE-2019-1969 [MEDIUM] CWE-264 CVE-2019-1969: A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Contro
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic. The vulnerability is due to an incorrect length check when the con
nvd
CVE-2021-1591P4MEDIUMCVSS 5.3v9.3\(4\)2021-08-25
CVE-2021-1591 [MEDIUM] CWE-284 CVE-2021-1591: A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches coul
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due to oversubscription of resources that occurs when applying ACLs to port channel interfaces. An att
nvd
CVE-2015-4301P4MEDIUMCVSS 6.8v11.1\(1c\)2015-08-19
CVE-2015-4301 [MEDIUM] CWE-399 CVE-2015-4301: Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of se
Cisco NX-OS on Nexus 9000 devices 11.1(1c) allows remote authenticated users to cause a denial of service (device hang) via large files that are copied to a device's filesystem, aka Bug ID CSCuu77225.
nvd
CVE-2015-4234P4HIGHCVSS 7.2v6.0\(2\)v6.2\(2\)2015-07-03
CVE-2015-4234 [HIGH] CWE-264 CVE-2015-4234: Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.
nvd
CVE-2020-3120P4MEDIUMCVSS 6.5≥ 5.2, < 6.2\(29\)≥ 7.3, < 8.4\(1a\)+12 more2020-02-05
CVE-2020-3120 [MEDIUM] CWE-190 CVE-2020-3120: A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software proce
nvd
CVE-2017-12342P4MEDIUMCVSS 6.8v7.0\(0\)hsk\(0.357\)v8.1\(1\)2017-11-30
CVE-2017-12342 [MEDIUM] CWE-264 CVE-2017-12342: A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow
A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow an unauthenticated, local attacker to read and send packets outside the scope of the OAC. The vulnerability is due to insufficient internal security measures in the OAC feature. An attacker could exploit this vulnerability by crafting specific packet
nvd
CVE-2019-1812P4MEDIUMCVSS 6.7≥ 6.0\(2\), < 7.0\(3\)i7\(5\)≥ 9.2, < 9.2\(2\)+2 more2019-05-15
CVE-2019-1812 [MEDIUM] CWE-347 CVE-2019-1812: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1813P4MEDIUMCVSS 6.7≥ 7.0\(3\)i1\(x\), < 7.0\(3\)i7\(5\)≥ 9.2, < 9.2\(2\)+2 more2019-05-15
CVE-2019-1813 [MEDIUM] CWE-347 CVE-2019-1813: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1811P4MEDIUMCVSS 6.7≥ 6.0\(2\), < 7.0\(3\)i7\(5\)≥ 9.2, < 9.2\(2\)+2 more2019-05-15
CVE-2019-1811 [MEDIUM] CWE-347 CVE-2019-1811: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attack
nvd
CVE-2019-1809P4MEDIUMCVSS 6.7≥ 7.3, < 8.1\(1a\)≥ 8.2, < 8.3\(1\)+3 more2019-05-15
CVE-2019-1809 [MEDIUM] CWE-347 CVE-2019-1809: A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an a
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulne
nvd
CVE-2017-12339P4MEDIUMCVSS 5.7v7.0\(0\)hsk\(0.357\)v8.0\(1\)+1 more2017-11-30
CVE-2017-12339 [MEDIUM] CWE-77 CVE-2017-12339: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attack
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI comman
nvd
CVE-2011-4023P4HIGHCVSS 7.8v5.0v5.0\(2\)+14 more2012-05-03
CVE-2011-4023 [HIGH] CWE-399 CVE-2011-4023: Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to caus
Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.
nvd
CVE-2014-3330P4MEDIUMCVSS 5.0v6.1\(2\)i2\(1\)2014-08-11
CVE-2014-3330 [MEDIUM] CWE-264 CVE-2014-3330: Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks f
Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489.
nvd
CVE-2021-1590P4MEDIUMCVSS 5.3v7.0\(3\)i4\(0.116\)v7.3\(7\)n1\(1b\)2021-08-25
CVE-2021-1590 [MEDIUM] CWE-787 CVE-2021-1590: A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerability is due to a logic error in the implementation of the system login block-for command when a
nvd
CVE-2016-1454P4MEDIUMCVSS 6.5fixed in 6.0\(2\)u6\(7\)≥ 6.1, < 7.0\(3\)i4\(1\)+9 more2016-10-06
CVE-2016-1454 [MEDIUM] CWE-20 CVE-2016-1454: Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
nvd
CVE-2019-1836P4HIGHCVSS 7.1v14.0\(3d\)2019-05-03
CVE-2019-1836 [HIGH] CWE-22 CVE-2019-1836: A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centr
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files. These system files may be sensitive and should not be overwritable by non-root users. The attacker would need valid device credential
nvd
CVE-2019-12662P4MEDIUMCVSS 6.7v8.1\(0.2\)s0v8.1\(1\)+2 more2019-09-25
CVE-2019-12662 [MEDIUM] CWE-347 CVE-2019-12662: A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, loca
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Op
nvd
CVE-2017-12331P4MEDIUMCVSS 6.7v8.1\(1\)2017-11-30
CVE-2017-12331 [MEDIUM] CWE-347 CVE-2017-12331: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and
nvd
CVE-2017-12333P4MEDIUMCVSS 6.7v8.1\(1\)2017-11-30
CVE-2017-12333 [MEDIUM] CWE-347 CVE-2017-12333: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypas
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and l
nvd