Known vulnerabilities in Cisco Nexus 9000 Series Switches
Vendor:
Cisco Systems, Inc
Software:
Cisco Nexus 9000 Series Switches
Software CPE:
cpe:2.3:h:cisco_systems:cisco_nexus_9000_series_switches:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
21
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
14.2(4i)
13.2(3n)
13.2(10e)
13.2(10f)
14.2(7f)
14.2(7l)
15.1(3e)
15.1(4c)
15.2(1g)
15.2(2f)
15.2(2e)
15.1(1h)
15.0(2e)
9.3(5.80)
9.3(5.106)
9.3(5.115)
9.3(5.127)
9.3(6)
10.1(0.324)
10.1(1)
13.0(2k)
13.0(1k)
7.0(3)I6(1)
7.0(3)I5(2)
7.0(3)I6(2)
7.0(3)I7(1)
7.0(3)I4(8)
8.1(0)BD(0.20)
7.0(3)I4(6)
4.0.179
6.1(2)I1(1)
7.0(3)I1(1)
6.1(2)I2(2a)
Vulnerabilities (21)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU114486 - Compiler Optimization Removal or Modification of Security-critical Code CVE-2025-20241 |
CWE-733 | Medium | - | 28.08.2025 |
SB2025082818 |
||
| #VU96606 - NULL Pointer Dereference CVE-2024-20446 |
CWE-476 | High | - | 29.08.2024 |
SB2024082903 |
||
| #VU86911 - Improper Access Control CVE-2024-20291 |
CWE-284 | Medium | - | 29.02.2024 |
SB2024022909 SB2024061419 SB2024061703 and 1 more |
||
| #VU67769 - Improper Access Control CVE-2021-27861 |
CWE-284 | Low | - | 30.09.2022 |
SB2022093010 |
||
| #VU67768 - Improper Access Control CVE-2021-27853 |
CWE-284 | Low | - | 30.09.2022 |
SB2022093009 |
||
| #VU66749 - Out-of-bounds read CVE-2022-20823 |
CWE-125 | Medium | - | 24.08.2022 |
SB2022082440 |
||
| #VU56103 - Improper input validation CVE-2021-1523 |
CWE-20 | Medium | 13.2.10e, 13.2.10f, 14.2.7f, 14.2.7l, 15.1.3e, 15.1.4c, 15.2.1g, 15.2.2e, 15.2.2f | 26.08.2021 |
SB2021082604 |
||
| #VU56102 - Insufficient Verification of Data Authenticity CVE-2021-1586 |
CWE-345 | Medium | 13.2.10e, 13.2.10f, 14.2.7f, 14.2.7l, 15.1.3e, 15.1.4c, 15.2.1g, 15.2.2e, 15.2.2f | 26.08.2021 |
SB2021082603 |
||
| #VU50381 - Improper Access Control CVE-2021-1389 |
CWE-284 | Medium | 9.3.5.80, 9.3.5.106, 9.3.5.115, 9.3.5.127, 9.3.6, 10.1.0.324, 10.1.1 | 04.02.2021 |
SB2021020507 |
||
| #VU13971 - Improper input validation CVE-2018-0372 |
CWE-20 | Low | 13.0.2k | 18.07.2018 |
SB2018072307 |
||
| #VU13415 - Resource exhaustion CVE-2018-0309 |
CWE-400 | Medium | 7.0.3 I4.8, 7.0.3 I6.2, 7.0.3 I7.1 | 20.06.2018 |
SB2018062114 |
||
| #VU9490 - Permissions, Privileges, and Access Controls CVE-2017-12351 |
CWE-264 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9488 - Command injection CVE-2017-12330 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9487 - Command injection CVE-2017-12329 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 SB2017120102 |
||
| #VU9486 - Improper input validation CVE-2017-12338 |
CWE-20 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9483 - Command injection CVE-2017-12336 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9482 - Command injection CVE-2017-12335 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9481 - Command injection CVE-2017-12334 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU9479 - Command injection CVE-2017-12339 |
CWE-77 | Low | - | 01.12.2017 |
SB2017120101 |
||
| #VU8895 - Improper input validation CVE-2017-12301 |
CWE-20 | Low | - | 19.10.2017 |
SB2017101807 |
Showing elements 1 - 20 out of 21