VendorsCisconexus_9500any version
Vulnerabilities

Cisco Nexus 9500 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2018-0301
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, causing a buffer overflow. The vulnerability is due to incorrect input validation in the authentication module of the NX-API subsystem. An attacker could exploit this vulnerability by sending a crafted HTTP or HTTPS packet to the management interface of an affected system with the NX-API feature enabled. An exploit could allow the attacker to execute arbitrary code as root. Note: NX-API is disabled by default. This vulnerability affects: MDS 9000 Series Multilayer Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvd45804, CSCve02322, CSCve02412.
Published 2018-06-20 · Modified
10.0EPSS 0.170
CVE-2019-1804
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Default SSH Key Vulnerability
Published 2019-05-03 · Modified
10.0EPSS 0.035
CVE-2024-20286
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20285
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2024-20284
Cisco NX-OS Software Python Parser Escape Vulnerability
Published 2024-08-28 · Analyzed
8.8EPSS 0.002
CVE-2019-1599
Cisco NX-OS Software Netstack Denial of Service Vulnerability
Published 2019-03-07 · Modified
8.6EPSS 0.143
CVE-2019-1616
Cisco NX-OS Software Cisco Fabric Services Denial of Service Vulnerability
Published 2019-03-11 · Modified
8.6EPSS 0.024
CVE-2022-20823
Cisco NX-OS Software OSPFv3 Denial of Service Vulnerability
Published 2022-08-25 · Modified
8.6EPSS 0.011
CVE-2021-1227
Cisco NX-OS Software NX-API Cross-Site Request Forgery Vulnerability
Published 2021-02-24 · Modified
8.1EPSS 0.007
CVE-2018-0295
A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the device unexpectedly reloading. The vulnerability is due to incomplete input validation of the BGP update messages. An attacker could exploit this vulnerability by sending a crafted BGP update message to the targeted device. An exploit could allow the attacker to cause the switch to reload unexpectedly. The Cisco implementation of the BGP protocol only accepts incoming BGP traffic from explicitly defined peers. To exploit this vulnerability, an attacker must be able to send the malicious packets over a TCP connection that appears to come from a trusted BGP peer or inject malformed messages into the victim's BGP network. This would require obtaining information about the BGP peers in the affected system's trusted network. The vulnerability may be triggered when the router receives a malformed BGP message from a peer on an existing BGP session. At least one BGP neighbor session must be established for a router to be vulnerable. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCve79599, CSCve87784, CSCve91371, CSCve91387.
Published 2018-06-20 · Modified
7.8EPSS 0.025
CVE-2018-0307
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI command. A successful exploit could allow the attacker, authenticated as a privileged user, to execute arbitrary commands with root privileges. Note: On products that support multiple virtual device contexts (VDC), this vulnerability could allow an attacker to access files from any VDC. This vulnerability affects Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCve51704, CSCve91749, CSCve91768.
Published 2018-06-20 · Modified
7.8EPSS 0.006
CVE-2019-1605
Cisco NX-OS Software NX-API Arbitrary Code Execution Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.005
CVE-2019-12717
Cisco NX-OS Software Virtualization Manager Command Injection Vulnerability
Published 2019-09-25 · Modified
7.8EPSS 0.004
CVE-2019-1604
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1726
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Published 2019-05-15 · Modified
7.8EPSS 0.004
CVE-2019-1601
Cisco NX-OS Software Unauthorized Filesystem Access Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1593
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2019-1585
Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2019-1602
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1596
Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability
Published 2019-03-07 · Modified
7.8EPSS 0.003
CVE-2019-1603
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.003
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1609
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)
Published 2019-03-08 · Modified
7.2EPSS 0.009
CVE-2019-1727
Cisco NX-OS Software Python Parser Privilege Escalation Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1612
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1612)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1611
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1728
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.002
CVE-2019-1836
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Symbolic Link Path Traversal Vulnerability
Published 2019-05-03 · Modified
7.1EPSS 0.004
CVE-2019-1732
Cisco NX-OS Software Remote Package Manager Command Injection Vulnerability
Published 2019-05-15 · Modified
6.9EPSS 0.004
CVE-2018-0291
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuw99630, CSCvg71290, CSCvj67977.
Published 2018-06-20 · Modified
6.8EPSS 0.021
CVE-2019-1600
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Published 2019-03-07 · Modified
6.7EPSS 0.004
CVE-2019-1733
Cisco NX-OS Software NX-API Sandbox Cross-Site Scripting Vulnerability
Published 2019-05-15 · Modified
5.4EPSS 0.009