Vulnerabilities > Cisco > NX OS > 6.1.4

DATE CVE VULNERABILITY TITLE RISK
2014-06-14 CVE-2014-3295 Improper Authentication vulnerability in Cisco Nx-Os
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
low complexity
cisco CWE-287
4.8
2014-05-26 CVE-2014-2201 Unspecified vulnerability in Cisco products
The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915.
network
low complexity
cisco
7.8
2014-05-26 CVE-2013-1191 Permissions, Privileges, and Access Controls vulnerability in Cisco products
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
network
high complexity
cisco CWE-264
7.1
2014-05-20 CVE-2013-6975 Path Traversal vulnerability in Cisco Nx-Os
Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217.
local
low complexity
cisco CWE-22
4.6
2014-01-08 CVE-2013-6982 Improper Input Validation vulnerability in Cisco Nx-Os
The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a crafted message, aka Bug ID CSCuj03174.
network
cisco CWE-20
4.3