Cisco
Cisco Nx-os: vulnerabilidades y CVE
Cisco Nx-os tiene 286 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE286
Últimos 12 meses1
Críticas5
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-20399 | Media (6.7) | 4.3% | ⚠ Explotación activa | 1 jul 2024 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20010 | Alta (7.4) | 0.18% | — | 25 feb 2026 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to… |
| CVE-2025-20292 | Media (4.4) | 3.2% | — | 27 ago 2025 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command injection attack on the underlying operating system of an affected device. To exploit this… |
| CVE-2025-20290 | Media (5.5) | 0.14% | — | 27 ago 2025 | A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series… |
| CVE-2025-20262 | Media (5) | 0.35% | — | 27 ago 2025 | A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated,… |
| CVE-2025-20241 | Alta (7.4) | 0.27% | — | 27 ago 2025 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an… |
| CVE-2025-20191 | Alta (7.4) | 0.24% | — | 7 may 2025 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an… |
| CVE-2024-20397 | Media (5.2) | 0.30% | — | 4 dic 2024 | This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image… |
| CVE-2024-20446 | Alta (8.6) | 0.78% | — | 28 ago 2024 | A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper… |
| CVE-2024-20413 | Media (6.7) | 0.15% | — | 28 ago 2024 | A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to… |
| CVE-2024-20411 | Media (6.7) | 0.16% | — | 28 ago 2024 | A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on an affected device. This vulnerability is due to… |
| CVE-2024-20289 | Media (4.4) | 0.23% | — | 28 ago 2024 | This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including crafted input as the argument of the affected command. A successful… |
| CVE-2024-20286 | Alta (8.8) | 0.19% | — | 28 ago 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system… |
| CVE-2024-20285 | Alta (8.8) | 0.19% | — | 28 ago 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system… |
| CVE-2024-20284 | Alta (8.8) | 0.19% | — | 28 ago 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system… |
| CVE-2024-20399 | Media (6.7) | 4.3% | ⚠ Explotación activa | 1 jul 2024 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected… |
| CVE-2024-20321 | Alta (8.6) | 0.71% | — | 29 feb 2024 | A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2024-20294 | Media (6.6) | 0.32% | — | 29 feb 2024 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an… |
| CVE-2024-20291 | Media (5.8) | 0.89% | — | 29 feb 2024 | A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send… |
| CVE-2024-20267 | Alta (8.6) | 0.93% | — | 29 feb 2024 | A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-20169 | Alta (7.4) | 0.33% | — | 23 ago 2023 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could… |
| CVE-2023-20168 | Media (6.5) | 0.24% | — | 23 ago 2023 | A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to… |
| CVE-2023-20115 | Media (5.4) | 0.58% | — | 23 ago 2023 | A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from… |
| CVE-2023-20185 | Alta (7.4) | 0.35% | — | 12 jul 2023 | A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted… |
| CVE-2023-20089 | Media (6.5) | 0.30% | — | 23 feb 2023 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause… |
| CVE-2023-20050 | Alta (7.8) | 0.25% | — | 23 feb 2023 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to… |
| CVE-2022-20650 | Alta (8.8) | 15% | — | 23 feb 2022 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation… |
| CVE-2022-20625 | Media (4.3) | 3.3% | — | 23 feb 2022 | A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service… |
| CVE-2022-20624 | Alta (7.5) | 12% | — | 23 feb 2022 | A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This… |
| CVE-2022-20623 | Alta (7.5) | 12% | — | 23 feb 2022 | A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
📰 Noticias relacionadas
Otros productos de Cisco
IOS · 625IOS XE · 581Adaptive Security Appliance Software · 354Secure Firewall Threat Defense · 299Unified Communications Manager · 241IOS XR · 213Identity Services Engine · 206Secure Firewall Management Center · 191Webex Meetings Server · 136Rv110w Firmware · 132Rv130w Firmware · 131Unified Computing System · 116