Search Results (Refine Search)
- CPE Product Version: cpe:/o:cisco:nx-os:6.2%282%29
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2015-6392 |
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171. Published: October 05, 2016; 9:59:01 PM -0400 |
V3.0: 7.5 HIGH V2.0: 7.8 HIGH |
CVE-2016-1409 |
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016. Published: May 29, 2016; 6:59:01 PM -0400 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
CVE-2016-1351 |
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279. Published: March 25, 2016; 9:59:05 PM -0400 |
V3.1: 7.5 HIGH V2.0: 7.8 HIGH |
CVE-2015-4234 |
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127. Published: July 03, 2015; 6:59:02 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2015-0658 |
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589. Published: March 27, 2015; 9:59:49 PM -0400 |
V3.x:(not available) V2.0: 7.9 HIGH |
CVE-2014-3341 |
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616. Published: August 19, 2014; 7:16:58 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2014-3295 |
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. Published: June 14, 2014; 12:26:47 AM -0400 |
V3.x:(not available) V2.0: 4.8 MEDIUM |
CVE-2014-2201 |
The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915. Published: May 25, 2014; 8:25:31 PM -0400 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2013-6975 |
Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217. Published: May 20, 2014; 7:13:37 AM -0400 |
V3.x:(not available) V2.0: 4.6 MEDIUM |
CVE-2014-0684 |
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136. Published: May 07, 2014; 6:55:04 AM -0400 |
V3.x:(not available) V2.0: 4.6 MEDIUM |
CVE-2013-6982 |
The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a crafted message, aka Bug ID CSCuj03174. Published: January 08, 2014; 4:55:06 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |