VendorsCisconexus_3500any version
Vulnerabilities

Cisco Nexus 3500 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2021-1361
Cisco NX-OS Software Unauthenticated Arbitrary File Actions Vulnerability
Published 2021-02-24 · Modified
9.8EPSS 0.016
CVE-2019-1614
Cisco NX-OS Software NX-API Command Injection Vulnerability
Published 2019-03-11 · Modified
9.0EPSS 0.041
CVE-2024-20286
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20285
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20284
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2019-1599
Cisco NX-OS Software Netstack Denial of Service Vulnerability
Published 2019-03-07 · Modified
8.6EPSS 0.143
CVE-2017-3883
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.
Published 2017-10-19 · Modified
8.6EPSS 0.045
CVE-2019-1598
Cisco FXOS and NX-OS Lightweight Directory Access Protocol Denial of Service Vulnerabilities
Published 2019-03-07 · Modified
8.6EPSS 0.025
CVE-2019-1597
Cisco FXOS and NX-OS Lightweight Directory Access Protocol Denial of Service Vulnerabilities
Published 2019-03-07 · Modified
8.6EPSS 0.025
CVE-2019-1616
Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2019-03-11 · Modified
8.6EPSS 0.024
CVE-2022-20823
Cisco NX-OS Software OSPFv3 Denial of Service Vulnerability
Published 2022-08-25 · Modified
8.6EPSS 0.011
CVE-2019-1605
Cisco NX-OS Software NX-API Arbitrary Code Execution Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.005
CVE-2019-1606
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)
Published 2019-03-08 · Modified
7.8EPSS 0.005
CVE-2019-1604
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1726
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Published 2019-05-15 · Modified
7.8EPSS 0.004
CVE-2019-1601
Cisco NX-OS Software Unauthorized Filesystem Access Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1593
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2019-1602
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1596
Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability
Published 2019-03-07 · Modified
7.8EPSS 0.003
CVE-2019-1603
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.003
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-1594
Cisco NX-OS Software 802.1X Extensible Authentication Protocol over LAN Denial of Service Vulnerability
Published 2019-03-06 · Modified
7.4EPSS 0.008
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1609
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)
Published 2019-03-08 · Modified
7.2EPSS 0.009
CVE-2019-1727
Cisco NX-OS Software Python Parser Privilege Escalation Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.
Published 2017-10-19 · Modified
7.2EPSS 0.005
CVE-2019-1612
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1612)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1611
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1730
Cisco NX-OS Software Bash Bypass Guest Shell Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.004
CVE-2019-1728
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.002
CVE-2019-1732
Cisco NX-OS Software Remote Package Manager Command Injection Vulnerability
Published 2019-05-15 · Modified
6.9EPSS 0.004
CVE-2024-20399
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2024-07-01 · Analyzed
6.7KEVEPSS 0.043
CVE-2019-1600
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Published 2019-03-07 · Modified
6.7EPSS 0.004
CVE-2019-1729
Cisco NX-OS Software Arbitrary File Overwrite Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.002
CVE-2019-1733
Cisco NX-OS Software NX-API Sandbox Cross-Site Scripting Vulnerability
Published 2019-05-15 · Modified
5.4EPSS 0.009