Decoding the world of cybersecurity

Cisco Nexus flaw enables remote root access

Cisco has patched a critical Nexus 9000 vulnerability that can allow an unauthenticated remote attacker to execute code with root privileges on affected Silicon One-based switches.

Cisco Nexus flaw enables remote root access
Summary
  • CVE-2026-20212 affects specified Cisco Nexus 9000 switches containing Silicon One ASICs and carries a CVSS score of 9.8.
  • Cisco says exposed TCP ports in the default Layer 3 VRF can allow unauthenticated remote code execution with root privileges.
  • Cisco has released fixes and temporary mitigations and says it is not aware of malicious exploitation.

Cisco has disclosed a critical vulnerability affecting specific Nexus 9000 switches that can allow an unauthenticated remote attacker to execute code with root privileges on the device.

CVE-2026-20212 carries a CVSS score of 9.8 and affects Nexus 9000 Series switches containing certain Silicon One application-specific integrated circuits. Cisco published the advisory on 2 September and has released software updates addressing the flaw.

The vulnerability exists because TCP ports 43210 and 43211 can be reached through the default Layer 3 virtual routing and forwarding instance on affected systems. Cisco says an attacker able to connect to the device can send crafted input that is then executed as code with root privileges.

Successful exploitation can also crash the S1HAL process, potentially forcing the affected switch to reload. The impact can therefore extend beyond confidentiality and administrative control to network availability.

Not every Nexus 9000 device is affected. Cisco lists a specific group of product identifiers containing the relevant Silicon One hardware and says other Nexus 9000 switches are not known to be vulnerable. Nexus 9000 fabric switches operating in ACI mode are also among the products Cisco lists as unaffected.

That product specificity is important for vulnerability triage. A critical advisory attached to a widely deployed product family can generate unnecessary disruption if operators assume that every system carrying the family name requires the same response. Hardware model and software release determine exposure in this case.

For affected deployments, however, the location of the flaw inside network infrastructure raises the operational stakes. Core and data-centre switches occupy a position of trust that can make administrative compromise materially different from compromise of an ordinary endpoint.

Root access to a network device can affect configuration integrity, traffic handling, availability, and the trust organisations place in the infrastructure carrying communications between systems. The possibility of forcing a reload also creates a direct resilience concern where redundancy is insufficient or maintenance windows are difficult to obtain.

Cisco has provided temporary mitigations for organisations that cannot immediately upgrade. Infrastructure access-control lists can be used to restrict management and control-plane traffic or explicitly deny TCP traffic destined for ports 43210 and 43211 on locally configured addresses.

The company has also released a Live Protect shield intended as a temporary mitigation for affected NX-OS deployments. Cisco stresses that these measures are not substitutes for moving to fixed software.

The Product Security Incident Response Team says it is not aware of public announcements or malicious exploitation of CVE-2026-20212. The vulnerability was discovered while Cisco was resolving a Technical Assistance Center support case rather than through observation of a known attack campaign.

That places the advisory in a different category from an actively exploited zero-day. There is a fix, temporary mitigation is available, and no malicious use has been identified. The combination of remote unauthenticated access, root-level code execution, and network-device impact nevertheless gives operators a strong reason to establish exposure before public technical knowledge spreads further.

The first task is consequently precise asset identification: whether a deployment contains one of the affected Silicon One-based Nexus models, whether its software release is vulnerable, and whether the relevant ports can be reached from networks where untrusted traffic is possible. Cisco’s fixed-software guidance then determines the permanent remediation path.

×