Vulnerabilities > Cisco > Nexus 2000

DATE CVE VULNERABILITY TITLE RISK
2019-03-11 CVE-2019-1614 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
network
low complexity
cisco CWE-77
critical
9.0
2019-03-11 CVE-2019-1611 Command Injection vulnerability in Cisco Fx-Os and Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
7.2
2019-03-08 CVE-2019-1605 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root.
local
low complexity
cisco CWE-20
7.2
2019-03-08 CVE-2019-1601 Improper Access Control vulnerability in Cisco Nx-Os
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file.
local
low complexity
cisco CWE-284
7.2
2017-10-19 CVE-2017-12301 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device.
local
low complexity
cisco CWE-20
7.2