VendorsCisconexus_6001any version
Vulnerabilities

Cisco Nexus 6001 Switch any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2022-20650
Cisco NX-OS Software NX-API Command Injection Vulnerability
Published 2022-02-23 · Modified
9.0EPSS 0.146
CVE-2015-0721
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, and CSCux88492.
Published 2016-10-06 · Modified
9.0EPSS 0.028
CVE-2020-3454
Cisco NX-OS Software Call Home Command Injection Vulnerability
Published 2020-08-27 · Modified
9.0EPSS 0.026
CVE-2020-3119
Cisco NX-OS Software Cisco Discovery Protocol Remote Code Execution Vulnerability
Published 2020-02-05 · Modified
8.8EPSS 0.048
CVE-2020-3172
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Arbitrary Code Execution and Denial of Service Vulnerability
Published 2020-02-26 · Modified
8.8EPSS 0.019
CVE-2021-1368
Cisco FXOS and NX-OS Software Unidirectional Link Detection Denial of Service and Arbitrary Code Execution Vulnerability
Published 2021-02-24 · Modified
8.8EPSS 0.005
CVE-2022-20824
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Denial of Service and Arbitrary Code Execution Vulnerability
Published 2022-08-25 · Modified
8.8EPSS 0.004
CVE-2017-3883
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability occurs because AAA processes prevent the NX-OS System Manager from receiving keepalive messages when an affected device receives a high rate of login attempts, such as in a brute-force login attack. System memory can run low on the FXOS devices under the same conditions, which could cause the AAA process to unexpectedly restart or cause the device to reload. An attacker could exploit this vulnerability by performing a brute-force login attack against a device that is configured with AAA security services. A successful exploit could allow the attacker to cause the affected device to reload. This vulnerability affects the following Cisco products if they are running Cisco FXOS or NX-OS System Software that is configured for AAA services: Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, Unified Computing System (UCS) 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuq58760, CSCuq71257, CSCur97432, CSCus05214, CSCux54898, CSCvc33141, CSCvd36971, CSCve03660.
Published 2017-10-19 · Modified
8.6EPSS 0.045
CVE-2018-0378
Cisco NX-OS Software for Nexus 5500, 5600, and 6000 Series Switches Precision Time Protocol Denial of Service Vulnerability
Published 2018-10-17 · Modified
8.6EPSS 0.040
CVE-2019-1858
Cisco FXOS and NX-OS Software Simple Network Management Protocol Denial of Service Vulnerability
Published 2019-05-16 · Modified
8.6EPSS 0.024
CVE-2019-1967
Cisco NX-OS Software Network Time Protocol Denial of Service Vulnerability
Published 2019-08-29 · Modified
8.6EPSS 0.020
CVE-2019-1962
Cisco NX-OS Software Cisco Fabric Services over IP Denial of Service Vulnerability
Published 2019-08-28 · Modified
8.6EPSS 0.020
CVE-2021-1387
Cisco NX-OS Software IPv6 Netstack Denial of Service Vulnerability
Published 2021-02-24 · Modified
8.6EPSS 0.014
CVE-2020-3517
Cisco FXOS and NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2020-08-27 · Modified
8.6EPSS 0.014
CVE-2022-20823
Cisco NX-OS Software OSPFv3 Denial of Service Vulnerability
Published 2022-08-25 · Modified
8.6EPSS 0.011
CVE-2021-1227
Cisco NX-OS Software NX-API Cross-Site Request Forgery Vulnerability
Published 2021-02-24 · Modified
8.1EPSS 0.007
CVE-2015-0658
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
Published 2015-03-28 · Modified
7.9EPSS 0.011
CVE-2015-6392
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.
Published 2016-10-06 · Modified
7.8EPSS 0.028
CVE-2015-6393
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka Bug IDs CSCuq39250, CSCus21733, CSCus21739, CSCut76171, and CSCux67182.
Published 2016-10-06 · Modified
7.8EPSS 0.028
CVE-2019-12717
Cisco NX-OS Software Virtualization Manager Command Injection Vulnerability
Published 2019-09-25 · Modified
7.8EPSS 0.004
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2019-1963
Cisco FXOS and NX-OS Software Authenticated Simple Network Management Protocol Denial of Service Vulnerability
Published 2019-08-28 · Modified
7.7EPSS 0.016
CVE-2019-1965
Cisco NX-OS Software Remote Management Memory Leak Denial of Service Vulnerability
Published 2019-08-28 · Modified
7.7EPSS 0.015
CVE-2019-1968
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.018
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1791
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.
Published 2017-10-19 · Modified
7.2EPSS 0.005
CVE-2019-1776
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1783
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1784
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1795
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1774
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1775
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1781
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1782
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1790
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-1770
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.004
CVE-2019-12662
Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.003
CVE-2016-1454
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Published 2016-10-06 · Modified
7.1EPSS 0.026
1 / 2Next →