Vulnerabilities > Cisco > Nexus 9508 > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-18 CVE-2018-0372 Resource Exhaustion vulnerability in Cisco Nx-Os 13.0(1K)
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denial of Service (DoS) condition on an affected system.
network
low complexity
cisco CWE-400
7.8
2018-06-21 CVE-2018-0306 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device.
local
low complexity
cisco CWE-78
7.2
2018-06-20 CVE-2018-0307 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device.
local
low complexity
cisco CWE-78
7.2
2018-06-20 CVE-2018-0295 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Border Gateway Protocol (BGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the device unexpectedly reloading.
network
low complexity
cisco CWE-20
7.8
2018-06-20 CVE-2018-0292 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Nx-Os
A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system.
low complexity
cisco CWE-119
8.3
2016-10-06 CVE-2016-1454 Improper Input Validation vulnerability in Cisco Nx-Os
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
network
cisco CWE-20
7.1
2016-10-06 CVE-2015-6393 Resource Management Errors vulnerability in Cisco Nx-Os
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka Bug IDs CSCuq39250, CSCus21733, CSCus21739, CSCut76171, and CSCux67182.
network
low complexity
cisco CWE-399
7.8
2016-10-06 CVE-2015-6392 Resource Management Errors vulnerability in Cisco Nx-Os
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.
network
low complexity
cisco CWE-399
7.8
2015-03-28 CVE-2015-0658 Improper Input Validation vulnerability in Cisco Nx-Os
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
7.9