Product:

Nx\-Os

(Cisco)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 278
Date Id Summary Products Score Patch Annotated
2016-10-06 CVE-2015-0721 Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, and CSCux88492. Nx\-Os 8.0
2016-03-03 CVE-2015-0718 Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579. Nx\-Os, Nx\-Os_1000v_switch, Unified_computing_system 7.5
2015-04-03 CVE-2015-0686 The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq92240. Nx\-Os N/A
2015-03-28 CVE-2015-0658 The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589. Nx\-Os N/A
2015-01-10 CVE-2015-0582 The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129. Nx\-Os N/A
2015-02-03 CVE-2014-8013 The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device reload) via a long CLI command, aka Bug ID CSCur54182. Nx\-Os N/A
2014-08-19 CVE-2014-3341 The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616. Nexus_5000, Nexus_5010, Nexus_5010p_switch, Nexus_5020, Nexus_5020p_switch, Nexus_5548p, Nexus_5548up, Nexus_5596t, Nexus_5596up, Nexus_56128p, Nexus_5672up, Nexus_6001, Nexus_6004, Nexus_6004x, Nx\-Os N/A
2014-08-11 CVE-2014-3330 Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489. Nexus_9000, Nx\-Os N/A
2014-06-14 CVE-2014-3295 The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. Nx\-Os N/A
2014-05-25 CVE-2014-3261 Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply,... Cg\-Os, Cgr_1120, Cgr_1240, Nexus_3016q, Nexus_3048, Nexus_3064t, Nexus_3064x, Nexus_3548, Nexus_4001i, Nexus_5000, Nexus_5010, Nexus_5010p_switch, Nexus_5020, Nexus_5020p_switch, Nexus_5548p, Nexus_5548up, Nexus_5596up, Nexus_7000, Nexus_7000_10\-Slot, Nexus_7000_18\-Slot, Nexus_7000_9\-Slot, Nx\-Os, Unified_computing_system_6120xp_fabric_interconnect, Unified_computing_system_6140xp_fabric_interconnect, Unified_computing_system_6248up_fabric_interconnect, Unified_computing_system_6296up_fabric_interconnect, Unified_computing_system_infrastructure_and_unified_computing_system_software N/A