Skip to finding
§
High
Edge — Network infrastructure
Confirmed
CVE-2026-20212

A routed unauthenticated caller can execute code as root on affected Cisco Nexus 9000 switches.

The exposed Silicon One services listen on TCP/43210 and TCP/43211 in the default Layer 3 VRF.

Affects

Cisco Nexus 9000 switches containing Cisco Silicon One ASICs and running NX-OS in standalone mode.

What it enables

Unauthenticated command execution as root on a network switch

Obtain routed reachability to a configured switch address in the default Layer 3 VRF.→↓Send crafted input to TCP/43210 or TCP/43211.→↓The S1HAL server executes the input as code with root privileges.
Why this matters

The established outcome is direct root execution from routed service reachability, not merely disruption of the switch.

Detail and 1 source
Required access

Network reachability to TCP/43210 or TCP/43211 on a locally configured switch address in the default Layer 3 VRF

Affected versions

N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808, Affected NX-OS releases identified by Cisco's Software Checker

A peer that can route to a locally configured switch address sends crafted input to the Silicon One Hardware Abstraction Layer service, which executes it with root privileges.

Cisco has published fixes, but exact version checks require its interactive Software Checker, no public reproducer is available, and pre-fix images remain accepted.

Evidence
Cisco explicitly states that crafted unauthenticated traffic can execute code as rootExact vulnerable and fixed NX-OS versions require the interactive Software Checker
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026