VendorsCisconexus_56128pall versions
Vulnerabilities

Cisco Nexus 56128P Switch

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

70CVEs
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1791
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.
Published 2017-10-19 · Modified
7.2EPSS 0.005
CVE-2019-1776
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1784
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1783
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1795
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1790
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1782
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1781
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1775
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1774
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1770
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.004
CVE-2018-0294
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear the device configuration and reload a device. An attacker could exploit this vulnerability by logging into an affected device as an administrative user and configuring an unauthorized account for the device. The account would not require a password for authentication and would be accessible only via a Secure Shell (SSH) connection to the device. A successful exploit could allow the attacker to configure an unauthorized account that has administrative privileges, does not require a password for authentication, and does not appear in the running configuration or the audit logs for the affected device. This vulnerability affects Firepower 4100 Series Next-Generation Firewalls, Firepower 9300 Security Appliance, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Fabric Extenders, Nexus 3500 Platform Switches, Nexus 4000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvd13993, CSCvd34845, CSCvd34857, CSCvd34862, CSCvd34879, CSCve35753.
Published 2018-06-20 · Modified
7.2EPSS 0.004
CVE-2019-12662
Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.003
CVE-2023-20168
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
Published 2023-08-23 · Modified
7.1EPSS 0.002
CVE-2018-0291
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuw99630, CSCvg71290, CSCvj67977.
Published 2018-06-20 · Modified
6.8EPSS 0.021
CVE-2018-0331
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Discovery Protocol message prior to processing it. An attacker with the ability to submit a Cisco Discovery Protocol message designed to trigger the issue could cause a DoS condition on an affected device while the device restarts. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, MDS 9000 Series Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvc89242, CSCve40943, CSCve40953, CSCve40965, CSCve40970, CSCve40978, CSCve40992, CSCve41000, CSCve41007.
Published 2018-06-21 · Modified
6.5EPSS 0.006
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
CVE-2021-1229
Cisco NX-OS Software ICMP Version 6 Memory Leak Denial of Service Vulnerability
Published 2021-02-24 · Modified
5.8EPSS 0.014
CVE-2019-1734
Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability
Published 2019-11-05 · Modified
5.5EPSS 0.003
CVE-2020-10136
IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
Published 2020-06-02 · Modified
5.3EPSS 0.285
CVE-2021-1590
Cisco NX-OS Software system login block-for Denial of Service Vulnerability
Published 2021-08-25 · Modified
5.3EPSS 0.014
CVE-2019-1731
Cisco NX-OS Software SSH Key Information Disclosure Vulnerability
Published 2019-05-15 · Modified
5.1EPSS 0.004
CVE-2014-3341
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
Published 2014-08-19 · Modified
5.0EPSS 0.047
CVE-2015-4237
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Published 2015-07-03 · Modified
4.6EPSS 0.004
CVE-2020-3504
Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability
Published 2020-08-27 · Modified
3.3EPSS 0.003
← Prev2 / 2