Description
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
Published: 2026-09-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits an unauthenticated, remote attacker with root privileges to execute arbitrary code. The flaw allows crafted input sent over TCP ports 43210 and 43211—both exposed by default in Layer 3 VRF—to be interpreted as code by the S1HAL process, potentially leading to a crash and a device reload. This is a type of insecure deserialization or input handling weakness identified as CWE‑1327, and it can compromise confidentiality, integrity, and availability of the switch.

Affected Systems

The affected products are Cisco NX‑OS software running on Cisco Nexus 3000 and Cisco Nexus 9000 series switches. No specific version details are provided, so any installation that includes the default Silicon One component and exposes ports 43210 or 43211 in the default VRF is vulnerable.

Risk and Exploitability

The CVSS score of 9.8 classifies this vulnerability as critical. EPSS data is not available, but the lack of a CISA KEV listing indicates that no publicly known exploits are reported yet. The attack can be launched over the unencrypted TCP ports 43210 and 43211 from any remote host with network reachability to the switch, requiring no authentication. Once exploited, the attacker gains root-level access and can execute code or cause a reboot, making the risk high for organizations that rely on these devices for network infrastructure.

Generated by OpenCVE AI on September 3, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Cisco NX‑OS software update that includes the S1HAL RCE fix or matches the version advisory published by Cisco.
  • Block or restrict inbound traffic to TCP ports 43210 and 43211 on the switch using firewall or ACL entries, and remove any unnecessary exposure of these ports in the default VRF.
  • If the switches will not require the Silicon One component, consider disabling it or removing the default VRF configuration to prevent the vulnerable interface from being reachable.

Generated by OpenCVE AI on September 3, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nx-os Software
Vendors & Products Cisco
Cisco nx-os Software

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with&nbsp;root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
Title Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
Weaknesses CWE-1327
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Nx-os Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-03T03:56:34.679Z

Reserved: 2025-10-08T11:59:15.398Z

Link: CVE-2026-20212

cve-icon Vulnrichment

Updated: 2026-09-02T17:56:55.931Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:31.547

Modified: 2026-09-03T13:04:38.177

Link: CVE-2026-20212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-1327

    Binding to an Unrestricted IP Address