VendorsCisconexus_9508all versions
Vulnerabilities

Cisco Nexus 9508

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

117CVEs
CVE-2019-1811
Cisco NX-OS CLI Command Software Image Signature Verification Vulnerabilities
Published 2019-05-15 · Modified
7.2EPSS 0.003
CVE-2016-1454
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Published 2016-10-06 · Modified
7.1EPSS 0.026
CVE-2023-20168
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
Published 2023-08-23 · Modified
7.1EPSS 0.002
CVE-2018-0291
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuw99630, CSCvg71290, CSCvj67977.
Published 2018-06-20 · Modified
6.8EPSS 0.021
CVE-2019-1613
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1613)
Published 2019-03-11 · Modified
6.7EPSS 0.004
CVE-2019-1615
Cisco NX-OS Software Image Signature Verification Vulnerability
Published 2019-03-11 · Modified
6.7EPSS 0.002
CVE-2019-1729
Cisco NX-OS Software Arbitrary File Overwrite Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.002
CVE-2024-20294
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the affected device through CLI show commands or Simple Network Management Protocol (SNMP) requests. A successful exploit could allow the attacker to cause the LLDP service to crash and stop running on the affected device. In certain situations, the LLDP crash may result in a reload of the affected device. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol).
Published 2024-02-28 · Analyzed
6.6EPSS 0.003
CVE-2016-6457
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).
Published 2016-11-19 · Modified
6.5EPSS 0.007
CVE-2018-0331
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Discovery Protocol message prior to processing it. An attacker with the ability to submit a Cisco Discovery Protocol message designed to trigger the issue could cause a DoS condition on an affected device while the device restarts. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, MDS 9000 Series Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvc89242, CSCve40943, CSCve40953, CSCve40965, CSCve40970, CSCve40978, CSCve40992, CSCve41000, CSCve41007.
Published 2018-06-21 · Modified
6.5EPSS 0.006
CVE-2019-1690
Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
Published 2019-03-11 · Modified
6.5EPSS 0.006
CVE-2022-20625
Cisco FXOS and NX-OS Software Cisco Discovery Protocol Service Denial of Service Vulnerability
Published 2022-02-23 · Modified
6.1EPSS 0.033
CVE-2015-4324
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to cause a denial of service (IGMP process restart) via a malformed IGMPv3 packet that is mishandled during memory allocation, aka Bug IDs CSCuv69713, CSCuv69717, CSCuv69723, CSCuv69732, and CSCuv48908.
Published 2015-08-19 · Modified
6.1EPSS 0.011
CVE-2015-4323
Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.9); Nexus 3000 devices 6.0(2)U5(1.41), 7.0(3)I2(0.373), and 7.3(0)ZN(0.83); Nexus 4000 devices 4.1(2)E1(1b); Nexus 7000 devices 6.2(14)S1; Nexus 9000 devices 7.3(0)ZN(0.9); and MDS 9000 devices 6.2 (13) and 7.1(0)ZN(91.99) and MDS SAN-OS 7.1(0)ZN(91.99) allows remote attackers to cause a denial of service (device outage) via a crafted ARP packet, related to incorrect MTU validation, aka Bug IDs CSCuv71933, CSCuv61341, CSCuv61321, CSCuu78074, CSCut37060, CSCuv61266, CSCuv61351, CSCuv61358, and CSCuv61366.
Published 2015-08-19 · Modified
6.1EPSS 0.010
CVE-2021-1229
Cisco NX-OS Software ICMP Version 6 Memory Leak Denial of Service Vulnerability
Published 2021-02-24 · Modified
5.8EPSS 0.014
CVE-2019-1969
Cisco NX-OS Software SNMP Access Control List Configuration Name Bypass Vulnerability
Published 2019-08-29 · Modified
5.8EPSS 0.014
CVE-2021-1591
Cisco Nexus 9500 Series Switches Access Control List Bypass Vulnerability
Published 2021-08-25 · Modified
5.8EPSS 0.010
CVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces.
Published 2024-02-28 · Analyzed
5.8EPSS 0.009
CVE-2019-1734
Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability
Published 2019-11-05 · Modified
5.5EPSS 0.003
CVE-2023-20115
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when an SFTP connection is opened to an affected device. An attacker could exploit this vulnerability by connecting and authenticating via SFTP as a valid, non-administrator user. A successful exploit could allow the attacker to read or overwrite files from the underlying operating system with the privileges of the authenticated user. There are workarounds that address this vulnerability.
Published 2023-08-23 · Modified
5.4EPSS 0.006
CVE-2020-10136
IP-in-IP protocol allows a remote, unauthenticated attacker to route arbitrary network traffic
Published 2020-06-02 · Modified
5.3EPSS 0.285
CVE-2021-1590
Cisco NX-OS Software system login block-for Denial of Service Vulnerability
Published 2021-08-25 · Modified
5.3EPSS 0.014
CVE-2019-1731
Cisco NX-OS Software SSH Key Information Disclosure Vulnerability
Published 2019-05-15 · Modified
5.1EPSS 0.004
CVE-2015-0775
The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(0)ZN(99.67) on Nexus 3000 devices allows remote attackers to cause a denial of service (login process reset) via an unspecified terminal-session request during TELNET session setup, aka Bug IDs CSCuo10554, CSCuu75466, CSCuu75471, CSCuu75484, CSCuu75498, CSCuu77170, and CSCuu77182.
Published 2015-06-12 · Modified
5.0EPSS 0.030
CVE-2015-4277
The global-configuration implementation on Cisco ASR 9000 devices with software 5.1.3 and 5.3.0 improperly closes vty sessions after a commit/end operation, which allows local users to cause a denial of service (tmp/*config file creation, memory consumption, and device hang) via unspecified vectors, aka Bug ID CSCut93842.
Published 2015-08-19 · Modified
4.9EPSS 0.003
CVE-2021-27853
L2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headers
Published 2022-09-27 · Modified
4.7EPSS 0.008
CVE-2020-3174
Cisco NX-OS Software Anycast Gateway Invalid ARP Vulnerability
Published 2020-02-26 · Modified
4.7EPSS 0.003
CVE-2021-1231
Cisco Nexus 9000 Series Fabric Switches ACI Mode Link Layer Discovery Protocol Port Denial of Service Vulnerability
Published 2021-02-24 · Modified
4.7EPSS 0.003
CVE-2015-4237
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Published 2015-07-03 · Modified
4.6EPSS 0.004
CVE-2015-4232
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.
Published 2015-07-03 · Modified
4.6EPSS 0.004
CVE-2019-1589
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Unmeasured Boot Vulnerability
Published 2019-05-03 · Modified
4.6EPSS 0.001
CVE-2021-1583
Cisco Nexus 9000 Series Fabric Switches ACI Mode Arbitrary File Read Vulnerability
Published 2021-08-25 · Modified
4.4EPSS 0.002
CVE-2019-1587
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Filter Query Information Disclosure Vulnerability
Published 2019-05-03 · Modified
4.3EPSS 0.012
CVE-2021-1367
Cisco NX-OS Software Protocol Independent Multicast Denial of Service Vulnerability
Published 2021-02-24 · Modified
4.3EPSS 0.004
CVE-2015-4213
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
Published 2015-06-24 · Modified
4.0EPSS 0.026
CVE-2015-4225
Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
Published 2015-06-27 · Modified
4.0EPSS 0.020
CVE-2020-3504
Cisco UCS Manager Software Local Management CLI Denial of Service Vulnerability
Published 2020-08-27 · Modified
3.3EPSS 0.003
← Prev3 / 3