CVE-2026-20212

CRITICALCVSS 9.8/10

Last modified

CVE-2026-20212 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges.

Description

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
CiscoCisco NX-OS Software10.3(1); 10.3(2); 10.3(3); 10.4(1); 10.3(99w); 10.3(3w); 10.3(99x); 10.3(3o); 10.3(4); 10.3(3p); 10.3(4a); 10.4(2); 10.3(3q); 10.3(5); 10.4(3); 10.3(3x); 10.3(4g); 10.5(1); 10.3(3r); 10.3(6); 10.4(4); 10.3(4h); 10.5(2); 10.3(7); 10.4(5); 10.5(3); 10.4(4g); 10.5(4); 10.6(1); 10.5(3t); 10.3(8); 10.4(6); 10.5(3s); 10.5(3e); 10.5(3o); 10.6(1s); 10.6(2); 10.5(3p); 10.3(9); 10.6(2s); 10.6(3); 10.4(7); 10.5(5); 10.6(2n); 10.6(3s)

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-20212?
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
How severe is CVE-2026-20212?
CVE-2026-20212 has a CVSS score of 9.8/10 (CRITICAL severity).
How do I fix CVE-2026-20212?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20212?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST