Vulnerabilities > Cisco > NX OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-11 CVE-2019-1613 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
4.6
2019-03-08 CVE-2019-1603 Improper Authorization vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level.
local
low complexity
cisco CWE-285
4.6
2019-03-07 CVE-2019-1600 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system.
local
low complexity
cisco CWE-732
4.4
2019-03-06 CVE-2019-1595 Improper Control of Dynamically-Managed Code Resources vulnerability in Cisco Nx-Os
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-913
6.1
2019-03-06 CVE-2019-1594 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2018-10-17 CVE-2018-0456 Improper Input Validation vulnerability in Cisco Nx-Os 9.2(0.43)
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly.
network
low complexity
cisco CWE-20
6.8
2018-10-17 CVE-2018-0395 Improper Input Validation vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads.
high complexity
cisco CWE-20
5.3
2018-06-21 CVE-2018-0331 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2018-06-21 CVE-2018-0309 Resource Exhaustion vulnerability in Cisco Nx-Os 7.0(3)I5(2)/7.0(3)I6(1)
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
6.8
2018-06-21 CVE-2018-0299 Improper Input Validation vulnerability in Cisco Nx-Os 4.1(2)E1(1R)
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
6.8