Binding to an Unrestricted IP Address in Cisco Nexus 9000 Series Switches - CVE-2026-20212

 

Binding to an Unrestricted IP Address in Cisco Nexus 9000 Series Switches - CVE-2026-20212

Published: September 2, 2026


Vulnerability identifier: #VU146763
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20212
CWE-ID: CWE-1327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to exposed network services in the Silicon One integration when connecting to TCP ports 43210 or 43211 in the default Layer 3 virtual routing and forwarding instance. A remote attacker can send crafted input to execute arbitrary code.

Successful exploitation may execute code with root privileges or cause the S1HAL process to crash, which could cause the device to reload.


Affected software

Cisco Nexus 9000 Series Switches

How to mitigate CVE-2026-20212

Install security update from vendor's website.

At the time of publication, Cisco Nexus 9000 Series Switches with the following product identifiers (PIDs) included a Silicon One ASIC:

  • N9324C-SE1U
  • N9348Y2C6D-SE1U
  • N9364E-SG2-O
  • N9364E-SG2-Q
  • N9396T12C-SE1
  • N9348Y12C-SE1
  • N9396Y12C-SE1
  • N9336C-SE1
  • N9K-C9804
  • N9K-C9808


Cisco Nexus 9000 Series Switches - addressed in versions 10.3.10, 10.4.8, 10.5.6, 10.6.4

External References

Related Security Bulletins