Vulnerabilities > Cisco > NX OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-02-24 CVE-2021-1231 Origin Validation Error vulnerability in Cisco Nx-Os
A vulnerability in the Link Layer Discovery Protocol (LLDP) for Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, adjacent attacker to disable switching on a small form-factor pluggable (SFP) interface.
low complexity
cisco CWE-346
4.7
2021-02-24 CVE-2021-1229 Memory Leak vulnerability in Cisco Nx-Os 15.1(2.31)/5.2(1)Sv5(1.3A)/8.4(3.53)
A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition.
network
low complexity
cisco CWE-401
5.3
2021-02-24 CVE-2021-1228 Unspecified vulnerability in Cisco Nx-Os
A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN.
low complexity
cisco
6.5
2021-02-24 CVE-2021-1227 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
cisco CWE-352
5.8
2021-02-04 CVE-2021-1389 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device.
network
low complexity
cisco
6.5
2020-08-27 CVE-2020-3398 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a BGP session to repeatedly reset, causing a partial denial of service (DoS) condition due to the BGP session being down.
network
cisco CWE-20
4.3
2020-08-27 CVE-2020-3338 Improper Handling of Exceptional Conditions vulnerability in Cisco Nx-Os
A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-755
5.0
2020-06-02 CVE-2020-10136 Authentication Bypass by Spoofing vulnerability in multiple products
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
network
low complexity
cisco digi hp treck CWE-290
5.3
2020-02-26 CVE-2020-3170 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart.
network
cisco CWE-20
4.3
2020-02-26 CVE-2020-3165 Use of Hard-coded Credentials vulnerability in Cisco Nx-Os
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device.
network
cisco CWE-798
4.3