VendorsCisconx-osany version
Vulnerabilities

Cisco Nx-os any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

140CVEs
CVE-2019-1611
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Published 2019-03-11 · Modified
7.2EPSS 0.005
CVE-2019-1779
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.005
CVE-2019-1780
Cisco FXOS and NX-OS Software Command Injection Vulnerability
Published 2019-05-16 · Modified
7.2EPSS 0.005
CVE-2019-1730
Cisco NX-OS Software Bash Bypass Guest Shell Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.004
CVE-2019-1812
Cisco NX-OS CLI Command Software Image Signature Verification Vulnerabilities
Published 2019-05-15 · Modified
7.2EPSS 0.003
CVE-2019-1813
Cisco NX-OS CLI Command Software Image Signature Verification Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.003
CVE-2019-1811
Cisco NX-OS CLI Command Software Image Signature Verification Vulnerabilities
Published 2019-05-15 · Modified
7.2EPSS 0.003
CVE-2019-1728
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Published 2019-05-15 · Modified
7.2EPSS 0.002
CVE-2016-1454
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Published 2016-10-06 · Modified
7.1EPSS 0.026
CVE-2023-20168
A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed request option is enabled for TACACS+ or RADIUS. An attacker could exploit this vulnerability by entering a crafted string at the login prompt of an affected device. A successful exploit could allow the attacker to cause the affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
Published 2023-08-23 · Modified
7.1EPSS 0.002
CVE-2019-1732
Cisco NX-OS Software Remote Package Manager Command Injection Vulnerability
Published 2019-05-15 · Modified
6.9EPSS 0.004
CVE-2018-0291
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the SNMP application to restart multiple times, leading to a system-level restart and a denial of service (DoS) condition. This vulnerability affects Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCuw99630, CSCvg71290, CSCvj67977.
Published 2018-06-20 · Modified
6.8EPSS 0.021
CVE-2013-3400
The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.
Published 2013-07-10 · Modified
6.8EPSS 0.004
CVE-2014-0676
Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.
Published 2014-01-22 · Modified
6.8EPSS 0.004
CVE-2012-4077
Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651.
Published 2013-10-14 · Modified
6.8EPSS 0.003
CVE-2012-4076
Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in a command that calls the system library function, aka Bug IDs CSCtf23559 and CSCtf27780.
Published 2013-10-14 · Modified
6.8EPSS 0.003
CVE-2012-4121
Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, CSCts56565, CSCts56570, and CSCts56574.
Published 2013-10-14 · Modified
6.8EPSS 0.003
CVE-2019-1600
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Published 2019-03-07 · Modified
6.7EPSS 0.004
CVE-2019-1810
Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.003
CVE-2019-1729
Cisco NX-OS Software Arbitrary File Overwrite Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.002
CVE-2019-1808
Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.002
CVE-2019-1809
Cisco NX-OS Software Patch Signature Verification Bypass Vulnerability
Published 2019-05-15 · Modified
6.7EPSS 0.002
CVE-2021-1389
Cisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass Vulnerability
Published 2021-02-04 · Modified
6.5EPSS 0.012
CVE-2018-0331
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain fields within a Cisco Discovery Protocol message prior to processing it. An attacker with the ability to submit a Cisco Discovery Protocol message designed to trigger the issue could cause a DoS condition on an affected device while the device restarts. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, MDS 9000 Series Multilayer Director Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvc89242, CSCve40943, CSCve40953, CSCve40965, CSCve40970, CSCve40978, CSCve40992, CSCve41000, CSCve41007.
Published 2018-06-21 · Modified
6.5EPSS 0.006
CVE-2013-5496
Open Network Environment Platform (ONEP) in Cisco NX-OS allows remote authenticated users to cause a denial of service (network-element reload) via a crafted packet, aka Bug ID CSCui51551.
Published 2013-09-16 · Modified
6.3EPSS 0.016
CVE-2012-4141
Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the "file name" parameter, aka Bug IDs CSCua71557 and CSCua71551.
Published 2013-10-05 · Modified
6.2EPSS 0.004
CVE-2012-4122
The CLI parser in Cisco NX-OS allows local users to bypass intended access restrictions, and overwrite or create arbitrary files, via shell output redirection, aka Bug IDs CSCts56672 and CSCts56669.
Published 2013-10-05 · Modified
6.2EPSS 0.003
CVE-2013-6683
The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attackers to cause a denial of service (NS processing outage) via a series of malformed packets, aka Bug ID CSCtd15904.
Published 2013-11-13 · Modified
6.1EPSS 0.007
CVE-2013-1226
The Ethernet frame-forwarding implementation in Cisco NX-OS on Nexus 7000 devices allows remote attackers to cause a denial of service (forwarding loop and service outage) via a crafted frame, aka Bug ID CSCug47098.
Published 2013-04-29 · Modified
6.1EPSS 0.007
CVE-2013-1208
The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers to intercept or modify network traffic by leveraging certain Layer 2 or Layer 3 access, aka Bug ID CSCud14691.
Published 2013-05-29 · Modified
5.8EPSS 0.009
CVE-2013-1212
The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a crafted certificate, aka Bug ID CSCud14837.
Published 2013-05-29 · Modified
5.8EPSS 0.007
CVE-2019-1734
Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability
Published 2019-11-05 · Modified
5.5EPSS 0.003
CVE-2013-1210
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and purple screen of death) by sending crafted STUN packets to a VEM, aka Bug ID CSCud14825.
Published 2013-05-29 · Modified
5.4EPSS 0.015
CVE-2013-1121
The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound routes, allows remote attackers to cause a denial of service (device reload) via a crafted AS path set, aka Bug ID CSCuf49554.
Published 2013-09-19 · Modified
5.4EPSS 0.011
CVE-2019-1733
Cisco NX-OS Software NX-API Sandbox Cross-Site Scripting Vulnerability
Published 2019-05-15 · Modified
5.4EPSS 0.009
CVE-2020-3170
Cisco NX-OS Software NX-API Denial of Service Vulnerability
Published 2020-02-26 · Modified
5.3EPSS 0.017
CVE-2019-1731
Cisco NX-OS Software SSH Key Information Disclosure Vulnerability
Published 2019-05-15 · Modified
5.1EPSS 0.004
CVE-2014-3341
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
Published 2014-08-19 · Modified
5.0EPSS 0.047
CVE-2015-0582
The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129.
Published 2015-01-10 · Modified
5.0EPSS 0.030
CVE-2012-4091
The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 message, aka Bug ID CSCtj73415.
Published 2013-10-05 · Modified
5.0EPSS 0.030
← Prev3 / 4Next →