Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
- ID
- 21144
- Status
- summarized
- Published
- 03 Sep 2026, 11:52 PM
- Fetched
- 04 Sep 2026, 1:53 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 04 Sep 2026, 1:57 AM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
Cisco disclosed CVE-2026-20212 (CVSS 9.8), a critical flaw in 10 specific Silicon One-based Nexus 9000 switch PIDs where TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF, allowing unauthenticated remote attackers to execute code as root or crash the S1HAL process and reload the device. Cisco has no fixed-release table yet—only iACL blocking and a temporary Live Protect shield as stopgaps—and separately bundled 7 umbrella CVEs into an IOS XR hardening release, 2 of which are also rated 9.8 with no workaround for any IOS XR version.
Why it matters
If your infrastructure runs any of the 10 listed Nexus 9000 PIDs (e.g., N9324C-SE1U, N9K-C9804) on NX-OS 10.3(1) through 10.6(3s), block ports 43210 and 43211 immediately via iACL and apply the Live Protect shield while waiting for a fixed release. Everyone else—including ACI-mode fabric switches, Nexus 3000/7000—is unaffected and needs no action.
Discussion angle
How many of us actually know which switch models and NX-OS versions our cloud or colo providers run underneath us—and whether a 'critical infrastructure CVE' like this is our problem or our provider's problem?