Vulnerabilities > Cisco > Nexus 93108Tc EX

DATE CVE VULNERABILITY TITLE RISK
2019-05-15 CVE-2019-1735 Argument Injection or Modification vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device.
local
low complexity
cisco CWE-88
7.2
2019-05-03 CVE-2019-1803 Permissions, Privileges, and Access Controls vulnerability in Cisco Nexus 9000 Series Application Centric Infrastructure
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrator rights to gain elevated privileges as the root user on an affected device.
local
low complexity
cisco CWE-264
7.2
2019-05-03 CVE-2019-1592 Improper Input Validation vulnerability in Cisco Nx-Os 14.1(0.90)
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affected device.
local
low complexity
cisco CWE-20
7.2
2019-05-03 CVE-2019-1589 Information Exposure vulnerability in Cisco Nx-Os 8.3(0)Sk(0.39)
A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive information on an affected device.
local
low complexity
cisco CWE-200
2.1
2019-05-03 CVE-2019-1587 Resource Management Errors vulnerability in Cisco Nx-Os 8.3(0)Sk(0.39)
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information.
network
low complexity
cisco CWE-399
4.0
2019-03-11 CVE-2019-1690 Unspecified vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device.
low complexity
cisco
3.3
2019-03-11 CVE-2019-1613 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
4.6
2018-07-18 CVE-2018-0372 Resource Exhaustion vulnerability in Cisco Nx-Os 13.0(1K)
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denial of Service (DoS) condition on an affected system.
network
low complexity
cisco CWE-400
7.8
2018-06-21 CVE-2018-0313 Injection vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit.
network
low complexity
cisco CWE-74
critical
9.0
2018-06-21 CVE-2018-0309 Resource Exhaustion vulnerability in Cisco Nx-Os 7.0(3)I5(2)/7.0(3)I6(1)
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
6.8