以下是对该漏洞描述的中文翻译,保持了技术术语的准确性与专业性: Cisco Nexus 9000 系列交换机中 Silicon One 集成组件存在一个漏洞,未认证的远程攻击者可借此执行具有 root 权限的代码。 该漏洞产生的原因是,在默认的三层(L3)虚拟路由和转发(VRF)中,TCP 端口 43210 和 43211 处于可访问状态。成功利用该漏洞后,攻击者可以连接到受影响的设备,并发送特制的输入数据,这些数据将以 root 权限作为代码执行。利用该漏洞还可能导致 S1HAL 进程崩溃,进而引发设备重新加载(
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco NX-OS Software | 10.3(1) |
affected |
10.3(2) |
affected | ||
10.3(3) |
affected | ||
10.4(1) |
affected | ||
10.3(99w) |
affected | ||
10.3(3w) |
affected | ||
10.3(99x) |
affected | ||
10.3(3o) |
affected | ||
| … +37 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco NX-OS Software | 10.3(1) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20279 | 9.8 CRITICAL | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20274 | 9.8 CRITICAL | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20280 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20278 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20275 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20276 | 8.6 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20277 | 8.2 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20281 | 7.5 HIGH | Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP |
| CVE-2026-20355 | 5.9 MEDIUM | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
| CVE-2026-20354 | 5.9 MEDIUM | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
No comments yet