AI Weekly Malaysia

Back to items Summaries

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

ID
21144
Status
summarized
Published
03 Sep 2026, 11:52 PM
Fetched
04 Sep 2026, 1:53 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
04 Sep 2026, 1:57 AM
Tags
Audience
developersdatabase_learnerssaas_founders

What happened

Cisco disclosed CVE-2026-20212 (CVSS 9.8), a critical flaw in 10 specific Silicon One-based Nexus 9000 switch PIDs where TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF, allowing unauthenticated remote attackers to execute code as root or crash the S1HAL process and reload the device. Cisco has no fixed-release table yet—only iACL blocking and a temporary Live Protect shield as stopgaps—and separately bundled 7 umbrella CVEs into an IOS XR hardening release, 2 of which are also rated 9.8 with no workaround for any IOS XR version.

Why it matters

If your infrastructure runs any of the 10 listed Nexus 9000 PIDs (e.g., N9324C-SE1U, N9K-C9804) on NX-OS 10.3(1) through 10.6(3s), block ports 43210 and 43211 immediately via iACL and apply the Live Protect shield while waiting for a fixed release. Everyone else—including ACI-mode fabric switches, Nexus 3000/7000—is unaffected and needs no action.

Discussion angle

How many of us actually know which switch models and NX-OS versions our cloud or colo providers run underneath us—and whether a 'critical infrastructure CVE' like this is our problem or our provider's problem?

Top