Vulnerabilities > Cisco > NX OS > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-07 CVE-2019-1599 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Nx-Os
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.
network
low complexity
cisco CWE-770
8.6
2019-03-07 CVE-2019-1598 Improper Input Validation vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2019-03-07 CVE-2019-1597 Improper Input Validation vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2019-03-07 CVE-2019-1596 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Nx-Os
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root.
local
low complexity
cisco CWE-732
7.8
2019-03-06 CVE-2019-1594 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
7.4
2019-03-06 CVE-2019-1593 Unspecified vulnerability in Cisco Nx-Os
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles.
local
low complexity
cisco
7.8
2019-03-06 CVE-2019-1591 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device.
local
low complexity
cisco CWE-78
7.8
2019-03-06 CVE-2019-1585 Configuration vulnerability in Cisco products
A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device.
local
low complexity
cisco CWE-16
7.8
2018-10-17 CVE-2018-0378 Improper Input Validation vulnerability in Cisco Nx-Os 7.3(2)N1(0.8)
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
8.6
2018-10-17 CVE-2018-0456 Improper Input Validation vulnerability in Cisco Nx-Os 9.2(0.43)
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly.
network
low complexity
cisco CWE-20
7.7