Impact
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits an unauthenticated, remote attacker with root privileges to execute arbitrary code. The flaw allows crafted input sent over TCP ports 43210 and 43211—both exposed by default in Layer 3 VRF—to be interpreted as code by the S1HAL process, potentially leading to a crash and a device reload. This is a type of insecure deserialization or input handling weakness identified as CWE‑1327, and it can compromise confidentiality, integrity, and availability of the switch.
Affected Systems
The affected products are Cisco NX‑OS software running on Cisco Nexus 3000 and Cisco Nexus 9000 series switches. No specific version details are provided, so any installation that includes the default Silicon One component and exposes ports 43210 or 43211 in the default VRF is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical. EPSS data is not available, but the lack of a CISA KEV listing indicates that no publicly known exploits are reported yet. The attack can be launched over the unencrypted TCP ports 43210 and 43211 from any remote host with network reachability to the switch, requiring no authentication. Once exploited, the attacker gains root-level access and can execute code or cause a reboot, making the risk high for organizations that rely on these devices for network infrastructure.
OpenCVE Enrichment