A routed unauthenticated caller can execute code as root on affected Cisco Nexus 9000 switches.
The exposed Silicon One services listen on TCP/43210 and TCP/43211 in the default Layer 3 VRF.
Cisco Nexus 9000 switches containing Cisco Silicon One ASICs and running NX-OS in standalone mode.
Unauthenticated command execution as root on a network switch
The established outcome is direct root execution from routed service reachability, not merely disruption of the switch.
Detail and 1 source
A peer that can route to a locally configured switch address sends crafted input to the Silicon One Hardware Abstraction Layer service, which executes it with root privileges.
Cisco has published fixes, but exact version checks require its interactive Software Checker, no public reproducer is available, and pre-fix images remain accepted.
- access:network:lan
- reachable from the local network
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
The pre-fix-image answer is an inference from Cisco’s documented downgrade support; Cisco’s advisory does not describe an anti-rollback change.