VendorsCisconx-osall versions
Vulnerabilities

Cisco Nx-os

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

271CVEs
CVE-2019-1604
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1726
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Published 2019-05-15 · Modified
7.8EPSS 0.004
CVE-2019-1601
Cisco NX-OS Software Unauthorized Filesystem Access Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1585
Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2019-1593
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
Published 2019-03-06 · Modified
7.8EPSS 0.004
CVE-2019-1602
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.004
CVE-2019-1618
Cisco Nexus 9000 Series Switches Standalone NX-OS Mode Tetration Analytics Agent Arbitrary Code Execution Vulnerability
Published 2019-03-11 · Modified
7.8EPSS 0.004
CVE-2019-1966
Cisco Unified Computing System Fabric Interconnect root Privilege Escalation Vulnerability
Published 2019-08-29 · Modified
7.8EPSS 0.004
CVE-2019-1592
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Privilege Escalation Vulnerability
Published 2019-05-03 · Modified
7.8EPSS 0.004
CVE-2018-0337
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected device. A successful exploit could allow the attacker to cause other users to execute unwanted, arbitrary commands on the affected device. Cisco Bug IDs: CSCvd06339, CSCvd15698, CSCvd36108, CSCvf52921, CSCvf52930, CSCvf52953, CSCvf52976.
Published 2018-06-21 · Modified
7.8EPSS 0.003
CVE-2019-1596
Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability
Published 2019-03-07 · Modified
7.8EPSS 0.003
CVE-2020-3394
Cisco Nexus 3000 and 9000 Series Switches Privilege Escalation Vulnerability
Published 2020-08-27 · Modified
7.8EPSS 0.003
CVE-2019-1603
Cisco NX-OS Software Privilege Escalation Vulnerability
Published 2019-03-08 · Modified
7.8EPSS 0.003
CVE-2023-20050
Cisco NX-OS Software CLI Command Injection Vulnerability
Published 2023-02-23 · Modified
7.8EPSS 0.003
CVE-2018-0456
Cisco NX-OS Software Authenticated Simple Network Management Protocol Denial of Service Vulnerability
Published 2018-10-17 · Modified
7.7EPSS 0.032
CVE-2018-0309
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect implementation of the CLI command, resulting in a failure to free all allocated memory upon completion. An attacker could exploit this vulnerability by authenticating to the affected device and repeatedly issuing a specific CLI command or sending a specific SNMP poll request for a specific Object Identifier (OID). A successful exploit could allow the attacker to cause the IP routing process to restart or to cause a device reset, resulting in a DoS condition. Cisco Bug IDs: CSCvf23136.
Published 2018-06-21 · Modified
7.7EPSS 0.020
CVE-2019-1963
Cisco FXOS and NX-OS Software Authenticated Simple Network Management Protocol Denial of Service Vulnerability
Published 2019-08-28 · Modified
7.7EPSS 0.016
CVE-2019-1965
Cisco NX-OS Software Remote Management Memory Leak Denial of Service Vulnerability
Published 2019-08-28 · Modified
7.7EPSS 0.015
CVE-2014-3261
Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
Published 2014-05-24 · Modified
7.6EPSS 0.020
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2018-0090
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to the NX-OS CPU for processing, leading to high CPU utilization and a denial of service (DoS) condition. The vulnerability is due to a bad code fix in the 7.3.2 code train that could allow traffic to the management interface to be misclassified and not match the proper configured ACLs. An attacker could exploit this vulnerability by sending crafted traffic to the management interface. An exploit could allow the attacker to bypass the configured management interface ACLs and impact the CPU of the targeted device, resulting in a DoS condition. This vulnerability affects the following Cisco products running Cisco NX-OS System Software: Multilayer Director Switches, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode. Cisco Bug IDs: CSCvf31132.
Published 2018-01-18 · Modified
7.5EPSS 0.026
CVE-2016-1455
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.
Published 2016-10-05 · Modified
7.5EPSS 0.024
CVE-2020-3338
Cisco NX-OS Software IPv6 Protocol Independent Multicast Denial of Service Vulnerability
Published 2020-08-27 · Modified
7.5EPSS 0.018
CVE-2019-1968
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.018
CVE-2020-3168
Cisco Nexus 1000V Switch for VMware vSphere Secure Login Enhancements Denial of Service Vulnerability
Published 2020-02-26 · Modified
7.5EPSS 0.016
CVE-2019-1977
Cisco Nexus 9000 Series Fabric Switches ACI Mode Border Leaf Endpoint Learning Vulnerability
Published 2019-08-29 · Modified
7.5EPSS 0.015
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2019-1617
Cisco Nexus 9000 Series Switches Standalone NX-OS Mode Fibre Channel over Ethernet NPV Denial of Service Vulnerability
Published 2019-03-11 · Modified
7.4EPSS 0.013
CVE-2019-1594
Cisco NX-OS Software 802.1X Extensible Authentication Protocol over LAN Denial of Service Vulnerability
Published 2019-03-06 · Modified
7.4EPSS 0.008
CVE-2018-0102
A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software attempts to free the same area of memory twice. An attacker could exploit this vulnerability by sending a pong request to an affected device from a location on the network that causes the pong reply packet to egress both a FabricPath port and a non-FabricPath port. An exploit could allow the attacker to cause a dual or quad supervisor virtual port-channel (vPC) to reload. This vulnerability affects the following products when running Cisco NX-OS Software Release 7.2(1)D(1), 7.2(2)D1(1), or 7.2(2)D1(2) with both the Pong and FabricPath features enabled and the FabricPath port is actively monitored via a SPAN session: Cisco Nexus 7000 Series Switches and Cisco Nexus 7700 Series Switches. Cisco Bug IDs: CSCuv98660.
Published 2018-01-18 · Modified
7.4EPSS 0.008
CVE-2019-1595
Cisco Nexus 5600 and 6000 Series Switches Fibre Channel over Ethernet Denial of Service Vulnerability
Published 2019-03-06 · Modified
7.4EPSS 0.006
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2021-1228
Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerability
Published 2021-02-24 · Modified
7.4EPSS 0.004
CVE-2023-20185
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites. Cisco has not released and will not release software updates that address this vulnerability.
Published 2023-07-12 · Modified
7.4EPSS 0.003
CVE-2023-20169
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the unexpected restart of the IS-IS process, which could cause the affected device to reload. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2 adjacent to the affected device.
Published 2023-08-23 · Modified
7.4EPSS 0.003
CVE-2023-20089
Cisco Nexus 9000 Series Fabric Switches in ACI Mode Link Layer Discovery Protocol Memory Leak Denial of Service Vulnerability
Published 2023-02-23 · Modified
7.4EPSS 0.003
CVE-2019-1767
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.010
CVE-2019-1768
Cisco NX-OS Software Buffer Overflow and Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.010
CVE-2019-1609
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)
Published 2019-03-08 · Modified
7.2EPSS 0.009
CVE-2017-12341
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software patch. An attacker could exploit this vulnerability by installing a crafted patch image with the vulnerable operation occurring prior to patch activation. An exploit could allow the attacker to execute arbitrary commands on an affected system as root. This vulnerability affects the following products running Cisco NX-OS System Software: Multilayer Director Switches, Nexus 2000 Series Fabric Extenders, Nexus 5000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Unified Computing System Manager. Cisco Bug IDs: CSCvf23735, CSCvg04072.
Published 2017-11-30 · Modified
7.2EPSS 0.007
← Prev3 / 7Next →