← All company news

CISCO SYSTEMS, INC. · News & developments

Cisco discloses critical vulnerabilities in Nexus switch software

Neutral

Cisco disclosed a critical NX-API vulnerability in NX-OS software that could let an unauthenticated remote attacker execute code with root privileges or cause a denial of service on affected devices. Cisco rated it 9.8 on the CVSS scale and said software updates address the flaw, with no workaround available. The advisory says the NX-API feature is disabled by default on Nexus 3000 and 9000 switches; affected UCS 6300 fabric interconnects have different authentication requirements.

Why this matters

For Cisco, the direct business exposure is uncertain because the advisory does not establish how many customers have vulnerable configurations, and Cisco says it is unaware of malicious use. The operational burden lands first on customers: they need to identify affected devices and schedule an upgrade, while Cisco’s advisory cautions that upgrades require checking hardware and software compatibility. That patching work can test customer confidence in the product, but the disclosure alone does not show a realized financial cost to Cisco.

Written with AI from the linked sources and reviewed by a SageNoodle editor. How we work.

Explore CISCO SYSTEMS, INC. research →