VendorsCisconexus_3064any version
Vulnerabilities

Cisco Nexus 3064 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2016-1329
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
Published 2016-03-03 · Modified
10.0EPSS 0.037
CVE-2020-3454
Cisco NX-OS Software Call Home Command Injection Vulnerability
Published 2020-08-27 · Modified
9.0EPSS 0.026
CVE-2020-3119
Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability
Published 2020-02-05 · Modified
8.8EPSS 0.048
CVE-2020-3172
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Arbitrary Code Execution and Denial of Service Vulnerability
Published 2020-02-26 · Modified
8.8EPSS 0.019
CVE-2020-3415
Cisco NX-OS Software Data Management Engine Remote Code Execution Vulnerability
Published 2020-08-27 · Modified
8.8EPSS 0.008
CVE-2022-20824
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability
Published 2022-08-25 · Modified
8.8EPSS 0.004
CVE-2024-20284
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20285
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20286
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2017-3883
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.
Published 2017-10-19 · Modified
8.6EPSS 0.045
CVE-2019-1967
Cisco NX-OS Software Network Time Protocol Denial of Service Vulnerability
Published 2019-08-29 · Modified
8.6EPSS 0.020
CVE-2020-3398
Cisco NX-OS Software Border Gateway Protocol Multicast VPN Session Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.018
CVE-2020-3397
Cisco NX-OS Software Border Gateway Protocol Multicast VPN Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.018
CVE-2021-1387
Cisco NX-OS Software IPv6 Netstack Denial of Service Vulnerability
Published 2021-02-24 · Modified
8.6EPSS 0.014
CVE-2020-3517
Cisco FXOS and NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.014
CVE-2022-20823
Cisco NX-OS Software OSPFv3 Denial of Service Vulnerability
Published 2022-08-25 · Modified
8.6EPSS 0.011
CVE-2020-3165
Cisco NX-OS Software Border Gateway Protocol MD5 Authentication Bypass Vulnerability
Published 2020-02-26 · Modified
8.2EPSS 0.016
CVE-2015-0658
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
Published 2015-03-28 · Modified
7.9EPSS 0.011
CVE-2019-1735
Cisco NX-OS Software Command Injection Vulnerability (CVE-2019-1735)
Published 2019-05-15 · Modified
7.8EPSS 0.005
CVE-2019-12717
Cisco NX-OS Software Virtualization Manager Command Injection Vulnerability
Published 2019-09-25 · Modified
7.8EPSS 0.004
CVE-2020-3394
Cisco Nexus 3000 and 9000 Series Switches Privilege Escalation Vulnerability
Published 2020-08-27 · Modified
7.8EPSS 0.003
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2018-0309
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect implementation of the CLI command, resulting in a failure to free all allocated memory upon completion. An attacker could exploit this vulnerability by authenticating to the affected device and repeatedly issuing a specific CLI command or sending a specific SNMP poll request for a specific Object Identifier (OID). A successful exploit could allow the attacker to cause the IP routing process to restart or to cause a device reset, resulting in a DoS condition. Cisco Bug IDs: CSCvf23136.
Published 2018-06-21 · Modified
7.7EPSS 0.020
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3338
Cisco NX-OS Software IPv6 Protocol Independent Multicast Denial of Service Vulnerability
Published 2020-08-27 · Modified
7.5EPSS 0.018
CVE-2019-1968
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.018
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1767
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.010
CVE-2019-1768
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.010
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.
Published 2017-10-19 · Modified
7.2EPSS 0.005
CVE-2019-1769
Cisco NX-OS Software Line Card Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1778
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1781
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1782
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-12662
Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.003
CVE-2024-20399
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2024-07-01 · Analyzed
6.7KEVEPSS 0.043
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
1 / 2Next →