Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-20212: Cisco Nexus 9000 Switches can be remotely taken over

CVE-2026-20212 · published 1 day ago
Summary

The Silicon One integration on Cisco Nexus 9000 series switches listens on two network ports that are open by default. An attacker on the network could connect to those ports, send specially crafted data, and gain full administrative control of the switch, even causing it to restart. Close or restrict access to ports 43210 and 43211, apply any available vendor updates, and limit network exposure of the switches.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco nx-os software 10.3(1)
Original advisory text
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability ...
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-1327Binding to an Unrestricted IP Address
Timeline
Published2 Sep 2026
Updated3 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-20212 · MITRE
Monitor software like this
Free during beta