VendorsCisconexus_3172all versions
Vulnerabilities

Cisco Nexus 3172

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2015-0721
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, and CSCux88492.
Published 2016-10-06 · Modified
9.0EPSS 0.028
CVE-2020-3454
Cisco NX-OS Software Call Home Command Injection Vulnerability
Published 2020-08-27 · Modified
9.0EPSS 0.026
CVE-2020-3119
Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability
Published 2020-02-05 · Modified
8.8EPSS 0.048
CVE-2020-3172
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Arbitrary Code Execution and Denial of Service Vulnerability
Published 2020-02-26 · Modified
8.8EPSS 0.019
CVE-2020-3415
Cisco NX-OS Software Data Management Engine Remote Code Execution Vulnerability
Published 2020-08-27 · Modified
8.8EPSS 0.008
CVE-2022-20824
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability
Published 2022-08-25 · Modified
8.8EPSS 0.004
CVE-2024-20284
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20285
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20286
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2019-1967
Cisco NX-OS Software Network Time Protocol Denial of Service Vulnerability
Published 2019-08-29 · Modified
8.6EPSS 0.020
CVE-2020-3398
Cisco NX-OS Software Border Gateway Protocol Multicast VPN Session Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.018
CVE-2020-3397
Cisco NX-OS Software Border Gateway Protocol Multicast VPN Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.018
CVE-2021-1387
Cisco NX-OS Software IPv6 Netstack Denial of Service Vulnerability
Published 2021-02-24 · Modified
8.6EPSS 0.014
CVE-2020-3517
Cisco FXOS and NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.014
CVE-2022-20823
Cisco NX-OS Software OSPFv3 Denial of Service Vulnerability
Published 2022-08-25 · Modified
8.6EPSS 0.011
CVE-2020-3165
Cisco NX-OS Software Border Gateway Protocol MD5 Authentication Bypass Vulnerability
Published 2020-02-26 · Modified
8.2EPSS 0.016
CVE-2015-0658
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
Published 2015-03-28 · Modified
7.9EPSS 0.011
CVE-2019-1735
Cisco NX-OS Software Command Injection Vulnerability (CVE-2019-1735)
Published 2019-05-15 · Modified
7.8EPSS 0.005
CVE-2019-12717
Cisco NX-OS Software Virtualization Manager Command Injection Vulnerability
Published 2019-09-25 · Modified
7.8EPSS 0.004
CVE-2020-3394
Cisco Nexus 3000 and 9000 Series Switches Privilege Escalation Vulnerability
Published 2020-08-27 · Modified
7.8EPSS 0.003
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2018-0309
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect implementation of the CLI command, resulting in a failure to free all allocated memory upon completion. An attacker could exploit this vulnerability by authenticating to the affected device and repeatedly issuing a specific CLI command or sending a specific SNMP poll request for a specific Object Identifier (OID). A successful exploit could allow the attacker to cause the IP routing process to restart or to cause a device reset, resulting in a DoS condition. Cisco Bug IDs: CSCvf23136.
Published 2018-06-21 · Modified
7.7EPSS 0.020
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3338
Cisco NX-OS Software IPv6 Protocol Independent Multicast Denial of Service Vulnerability
Published 2020-08-27 · Modified
7.5EPSS 0.018
CVE-2019-1968
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.018
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1767
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.010
CVE-2019-1768
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.010
CVE-2019-1769
Cisco NX-OS Software Line Card Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1778
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1781
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1782
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-12662
Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.003
CVE-2016-1454
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Published 2016-10-06 · Modified
7.1EPSS 0.026
CVE-2024-20399
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2024-07-01 · Analyzed
6.7KEVEPSS 0.043
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
CVE-2015-4324
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Published 2015-08-19 · Modified
6.1EPSS 0.011
1 / 2Next →