Nx Os
Vendor:
First CVE: Sep 8, 2009 · Active for 16 years
275
Total CVEs
More Total CVEs than 100% of tracked products
18.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Nx Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2009
16 years ago
Most Recent CVE
Aug 28, 2024
699 days ago
CVE Severity & Scoring
Nx Os275 CVEs
56%
41%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local91 (33.1%)
Network81 (29.5%)
Unknown74 (26.9%)
Physical1 (0.4%)
Adjacent Network28 (10.2%)
Attack Complexity
Low194 (70.5%)
High7 (2.5%)
Unknown74 (26.9%)
User Interaction
None195 (70.9%)
Unknown74 (26.9%)
Required6 (2.2%)
Privileges Required
Low51 (18.5%)
High56 (20.4%)
None94 (34.2%)
Unknown74 (26.9%)
Top CVEs
Signals from CVEs in this product scope (275 CVEs).
275 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2024-20399MEDIUM A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underly | Jul 1, 2024 | 6.7 | 63 | YES | NO |
CVE-2018-0301CRITICAL A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management interface on an affected system, c | Jun 20, 2018 | 9.8 | 39 | NO | NO |
CVE-2022-20650HIGH A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is | Feb 23, 2022 | 8.8 | 35 | NO | NO |
CVE-2019-1599HIGH A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. Th | Mar 7, 2019 | 8.6 | 34 | NO | NO |
CVE-2018-0310CRITICAL A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive informati | Jun 21, 2018 | 9.8 | 32 | NO | NO |
CVE-2022-20624HIGH A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con | Feb 23, 2022 | 7.5 | 31 | NO | NO |
CVE-2022-20623HIGH A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated | Feb 23, 2022 | 7.5 | 30 | NO | NO |
CVE-2021-1361CRITICAL A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that | Feb 24, 2021 | 9.1 | 30 | NO | NO |
CVE-2020-10136MEDIUM IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and o | Jun 2, 2020 | 5.3 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (275 CVEs).
CISA KEV
2 CVEs
0.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.4% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (275 CVEs).
Media Mentions
Signals from CVEs in this product scope (275 CVEs).
Top CNAs Publishing CVEs For Nx Os
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| r231 | 1 | 5.3 | 0.8% | 0 | 0 |
| base | 7 | 7.8 | 3.2% | 0 | 0 |
| 9.9\(0.902\) | 1 | 9.8 | 4.2% | 0 | 0 |
| 9.4\(2\) | 1 | 6.7 | 4.3% | 1 | 0 |
| 9.4\(1a\) | 1 | 6.7 | 4.3% | 1 | 0 |
| 9.4\(1\) | 1 | 6.7 | 4.3% | 1 | 0 |
| 9.3\(9\) | 5 | 7.2 | 1.3% | 1 | 0 |
| 9.3\(8.15\) | 1 | 4.3 | 3.3% | 0 | 0 |
| 9.3\(8\) | 5 | 7.2 | 1.3% | 1 | 0 |
| 9.3\(7a\) | 5 | 7.2 | 1.3% | 1 | 0 |
| 9.3\(7\) | 6 | 7.4 | 1.3% | 1 | 0 |
| 9.3\(6\) | 6 | 7.5 | 1.4% | 1 | 0 |
| 9.3\(5\) | 9 | 7.3 | 2.4% | 1 | 0 |
| 9.3\(4\) | 6 | 6.9 | 1.3% | 1 | 0 |
| 9.3\(3\)idi9\(0.569\) | 1 | 8.1 | 0.7% | 0 | 0 |
| 9.3\(3\) | 7 | 7.4 | 2.9% | 1 | 0 |
| 9.3\(2a\) | 2 | 6.7 | 2.3% | 1 | 0 |
| 9.3\(2\) | 6 | 7.3 | 1.8% | 1 | 0 |
| 9.3\(1z\) | 1 | 8.6 | 1.4% | 0 | 0 |
| 9.3\(13\) | 4 | 8.3 | 1.2% | 1 | 0 |