VendorsCisconexus_7000any version
Vulnerabilities

Cisco Nexus 7000 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2019-1605
Cisco NX-OS Software NX-API Arbitrary Code Execution Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.005
CVE-2019-1735
Cisco NX-OS Software Command Injection Vulnerability (CVE-2019-1735)
Published 2019-05-15 · Modified
7.8EPSS 0.005
CVE-2019-12717
Cisco NX-OS Software Virtualization Manager Command Injection Vulnerability
Published 2019-09-25 · Modified
7.8EPSS 0.004
CVE-2019-1604
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1726
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Published 2019-05-15 · Modified
7.8EPSS 0.004
CVE-2019-1601
Cisco NX-OS Software Unauthorized Filesystem Access Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1593
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2018-0337
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected device. A successful exploit could allow the attacker to cause other users to execute unwanted, arbitrary commands on the affected device. Cisco Bug IDs: CSCvd06339, CSCvd15698, CSCvd36108, CSCvf52921, CSCvf52930, CSCvf52953, CSCvf52976.
Published 2018-06-21 · Modified
7.8EPSS 0.003
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2014-3261
Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
Published 2014-05-24 · Modified
7.6EPSS 0.020
CVE-2020-3338
Cisco NX-OS Software IPv6 Protocol Independent Multicast Denial of Service Vulnerability
Published 2020-08-27 · Modified
7.5EPSS 0.018
CVE-2019-1968
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.018
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2019-1594
Cisco NX-OS Software 802.1X Extensible Authentication Protocol over LAN Denial of Service Vulnerability
Published 2019-03-06 · Modified
7.4EPSS 0.008
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1609
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)
Published 2019-03-08 · Modified
7.2EPSS 0.009
CVE-2019-1727
Cisco NX-OS Software Python Parser Privilege Escalation Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain Python functions within the scripting sandbox of the affected device. An attacker could exploit this vulnerability to escape the scripting sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. To exploit this vulnerability, an attacker must have local access and be authenticated to the targeted device with administrative or Python execution privileges. These requirements could limit the possibility of a successful exploit. This vulnerability affects the following Cisco products if they are running Cisco NX-OS Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches - Standalone, NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvb86832, CSCvd86474, CSCvd86479, CSCvd86484, CSCvd86490, CSCve97102, CSCvf12757, CSCvf12804, CSCvf12815, CSCvf15198.
Published 2017-10-19 · Modified
7.2EPSS 0.005
CVE-2019-1783
Cisco NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1781
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1782
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-1607
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1607)
Published 2019-03-08 · Modified
7.2EPSS 0.005
CVE-2019-1608
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1608)
Published 2019-03-08 · Modified
7.2EPSS 0.005
CVE-2019-1611
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1730
Cisco NX-OS Software Bash Bypass Guest Shell Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.004
CVE-2019-1728
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.002
CVE-2013-1191
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
Published 2014-05-24 · Modified
7.1EPSS 0.019
CVE-2014-2200
Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629.
Published 2014-05-24 · Modified
7.1EPSS 0.019
CVE-2023-20168
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
Published 2023-08-23 · Modified
7.1EPSS 0.002
CVE-2018-0291
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuw99630, CSCvg71290, CSCvj67977.
Published 2018-06-20 · Modified
6.8EPSS 0.021
CVE-2024-20399
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2024-07-01 · Analyzed
6.7KEVEPSS 0.043
CVE-2019-1600
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Published 2019-03-07 · Modified
6.7EPSS 0.004
CVE-2018-0331
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Discovery Protocol message prior to processing it. An attacker with the ability to submit a Cisco Discovery Protocol message designed to trigger the issue could cause a DoS condition on an affected device while the device restarts. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, MDS 9000 Series Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvc89242, CSCve40943, CSCve40953, CSCve40965, CSCve40970, CSCve40978, CSCve40992, CSCve41000, CSCve41007.
Published 2018-06-21 · Modified
6.5EPSS 0.006
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
CVE-2015-4324
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Published 2015-08-19 · Modified
6.1EPSS 0.011
CVE-2015-4197
Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415.
Published 2015-06-20 · Modified
6.1EPSS 0.010
CVE-2015-4323
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.9); Nexus 3000 devices 6.0(2)U5(1.41), 7.0(3)I2(0.373), and 7.3(0)ZN(0.83); Nexus 4000 devices 4.1(2)E1(1b); Nexus 7000 devices 6.2(14)S1; Nexus 9000 devices 7.3(0)ZN(0.9); and MDS 9000 devices 6.2 (13) and 7.1(0)ZN(91.99) and MDS SAN-OS 7.1(0)ZN(91.99) allows remote attackers to cause a denial of service (device outage) via a crafted ARP packet, related to incorrect MTU validation, aka Bug IDs CSCuv71933, CSCuv61341, CSCuv61321, CSCuu78074, CSCut37060, CSCuv61266, CSCuv61351, CSCuv61358, and CSCuv61366.
Published 2015-08-19 · Modified
6.1EPSS 0.010
CVE-2013-1226
The Ethernet frame-forwarding implementation in Cisco NX-OS on Nexus 7000 devices allows remote attackers to cause a denial of service (forwarding loop and service outage) via a crafted frame, aka Bug ID CSCug47098.
Published 2013-04-29 · Modified
6.1EPSS 0.007
← Prev2 / 3Next →