CVE-2026-20212
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.53%
- CWE
- CWE-1327
- Published
- 2026-09-02
- Last modified
- 2026-09-03
Affected products
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
- Cisco Cisco NX-OS Software
Weakness type
Related vulnerabilities
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-0481 — Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a...
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls
- CVE-2026-24015 — Apache IoTDB: Insecure Default Configuration Vulnerability