
[CIVN-2026-0436] Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Systems Affected
N9324C-SE1U
N9348Y2C6D-SE1U
N9364E-SG2-O
N9364E-SG2-Q
N9396T12C-SE1
N9348Y12C-SE1
N9396Y12C-SE1
N9336C-SE1
N9K-C9804
N9K-C9808
Overview
A vulnerability has been reported in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to remote attacker to execute code with root privileges.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating in Software.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). An attacker could exploit this vulnerability by sending crafted input that could be executed as code with root privileges.
Successful exploitation of this vulnerability could allow the attacker the S1HAL process to crash, which could cause the device to reload.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
CVE Name
CVE-2026-20212
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZiroACgkQ3jCgcSdc
ys98Tg/+K39piXg8pS2tVnB/piT2OyYF743LKawWwFhJ8MVRQhEZ7v6sF195fc6v
CWXZZoPMjGOHmkc2XbDjZhJPfxT4rtj3krUq3WJ8495SXfZTPJAYbnucb74mSOvQ
0xuHDR/zFOqZiEf20G3mLeTNxPv4aj0KdD2LH6yhsqehu7j0Ro++HAsNEdoA25Bs
1HRFfXpdX9Dt+N6yvYQ0mQXdeJvlLn2c0oHRu2NvWbD5uRr2clhoKnKhQbQWlIhc
AMil6GjzQnKdN/kyU2VQmioB5NMTKNsmabecKVBG+CVC9pnoNlZY/fIaevXVter4
/V4ST0CpqGwREX2qXgqdoA9EzWBGLztUrQ9pYXfPQZDT0JGKgnV4Du0iUAq4yJ70
CcO3WpPGkTLw3wXS89mZreaQX4cR5Kp3S5y7rIJ8h02vA5KmyqGfKd2vukdlzfaM
2LZWPW/poNQovjuQwb5RrYEwHM+mAi8GsuLTVqKY+aA60PO9+U22PdtTv00m+gzo
zB7vIuQLyCBDpicPEcSEgqXcnIZcPP4WHCWSHq5dLOUanh0cmifGxNXi5uthrEkq
/eDTPpW1N7jlSpaz+PPTLJVw1B5dWwF74yU1kQQ/E7cWm9h6xdIrGuxTHX2jTnCt
CCRhdPPNwEZewZ4+BwwhzifVFbDpQrAivu4/VWFgpwe/ORZdlVU=
=Clvz
—–END PGP SIGNATURE—–


