Known vulnerabilities in Cisco NX-OS Software

Software CPE: cpe:2.3:h:cisco_systems:cisco_nx-os:*:*:*:*:*:*:*:*
Total vulnerabilities: 106
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 10

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco NX-OS Software Cisco NX-OS Software is affected by 106 known vulnerabilities: 1 critical, 20 high, 49 medium, 35 low Critical High Medium Low

Vulnerabilities (106)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU154019 - Heap-based Buffer Overflow
CVE-2026-76471
CWE-122 Critical
No
No
10.3(10), 10.4(8), 10.5(6), 10.6(4) 09.10.2026 SB2026100901
SB2026100902
#VU154016 - Out-of-bounds read
CVE-2026-76457
CWE-125 High
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154017 - Improper Check or Handling of Exceptional Conditions
CVE-2026-76458
CWE-703 High
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154018 - Stack-based buffer overflow
CVE-2026-76459
CWE-121 Medium
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154013 - Command injection
CVE-2026-76453
CWE-77 Medium
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154014 - Improper Access Control
CVE-2026-76455
CWE-284 High
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154015 - Improper input validation
CVE-2026-76456
CWE-20 High
No
No
8.4(14), 9.4(5a), 10.3(10), 10.4(8), 10.5(6), 10.6(4), 16.0(9h), 16.1(6g), 16.2(3g) 08.10.2026 SB2026100865
SB2026100901
#VU154012 - Improper isolation or compartmentalization
CVE-2026-20032
CWE-653 Low
No
No
10.3(10), 10.4(8), 10.5(6), 10.6(4) 08.10.2026 SB2026100865
#VU154011 - Allocation of Resources Without Limits or Throttling
CVE-2026-20173
CWE-770 Medium
No
No
8.4(13) 08.10.2026 SB2026100864
#VU132081 - Always-Incorrect Control Flow Implementation
CVE-2026-20171
CWE-670 Medium
No
No
10.3(9), 10.4(7), 10.5(4), 10.5(5), 10.6(2) 21.05.2026 SB2026052147
#VU123291 - Buffer Access with Incorrect Length Value
CVE-2026-20010
CWE-805
No
No
10.3(5), 10.4(3), 16.0(9e) 26.02.2026 SB2026022616
#VU123290 - Buffer Access with Incorrect Length Value
CVE-2026-20033
CWE-805 Low
No
No
10.6(2), 16.1(5e), 16.2(1g) 26.02.2026 SB2026022615
#VU123288 - Uncontrolled Memory Allocation
CVE-2026-20048
CWE-789 Medium
No
No
16.1(5e), 16.2(1g) 26.02.2026 SB2026022614
#VU123287 - Use of Uninitialized Variable
CVE-2026-20051
CWE-457 Medium
No
No
10.6(2) 26.02.2026 SB2026022613
#VU114566 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20292
CWE-78 Low
No
No
4.3(6a), 4.3(6a)UCSM, 4.3(6b), 4.3(6c), 7.3(16)N1(1), 8.4(11), 8.4(12), 9.3(5)I42(3j), 9.3(5)I43(6a), 9.3(5)I43(6a.88), 9.3(5)I43(6b), 9.3(5)I43(6b.1), 9.3(15), 9.4(3b), 9.4(4), 10.2(9), 10.3(7), 10.3(8), 10.4(2)I43(6a), 10.4(2)I43(6a.34), 10.4(5), 10.5(1)I60(1a), 10.5(1)I60(1a.124), 10.5(3), 10.6(1), 16.0(9e), 16.1(4h) 29.08.2025 SB2025082978
#VU114564 - Exposure of sensitive information to an unauthorized actor
CVE-2025-20290
CWE-200 Low
No
No
4.3(6c), 4.3(6c)UCSM, 9.3(5)I42(3j), 9.3(5)I43(6b), 9.3(5)I43(6b.24), 10.3(8), 10.4(2)I43(6b), 10.4(2)I43(6b.4), 10.4(2)I43(6b.8), 10.5(1)I60(1a), 10.5(1)I60(1a.45), 10.5(1)I60(1a.250), 10.6(1) 29.08.2025 SB2025082954
#VU114491 - NULL Pointer Dereference
CVE-2025-20262
CWE-476 Medium
No
No
9.3(15), 10.2(9), 10.3(7), 10.3(8), 10.4(5), 10.5(3), 10.6(1) 28.08.2025 SB2025082833
#VU114486 - Compiler Optimization Removal or Modification of Security-critical Code
CVE-2025-20241
CWE-733 Medium
No
No
9.3(15), 10.2(9), 10.3(7), 10.3(8), 10.4(5), 10.6(1) 28.08.2025 SB2025082818
#VU108841 - Buffer Access with Incorrect Length Value
CVE-2025-20191
CWE-805 Medium
No
No
8.4(10), 8.4(11), 9.3(15), 10.2(9), 10.3(6), 10.3(7), 10.4(4), 10.4(5), 10.5(1), 10.5(2), 10.5(3) 09.05.2025 SB2025050948
#VU85808 - NULL Pointer Dereference
CVE-2024-0727
CWE-476 Medium
No
No
9.4(2) 25.01.2024 SB2024012552
SB2024020525
SB2024021323
and 100 more


Showing elements 1 - 20 out of 106