Binding to an Unrestricted IP Address in Cisco Nexus 9000 Series Switches - CVE-2026-20212
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to exposed network services in the Silicon One integration when connecting to TCP ports 43210 or 43211 in the default Layer 3 virtual routing and forwarding instance. A remote attacker can send crafted input to execute arbitrary code.
Successful exploitation may execute code with root privileges or cause the S1HAL process to crash, which could cause the device to reload.
Affected software
How to mitigate CVE-2026-20212
Install security update from vendor's website.
At the time of publication, Cisco Nexus 9000
Series Switches with the following product identifiers (PIDs) included a
Silicon One ASIC: