← Terug naar overzicht

A critical vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches allows an unauthenticated remote attacker to execute arbitrary code with root privileges. The flaw exists due to TCP ports 43210 and 43211 being accessible by default in the Layer 3 virtual routing and forwarding (VRF) context. An attacker can connect to these open ports and send specially crafted input to trigger code execution at the root level. Additionally, successful exploitation can crash the S1HAL process, potentially causing the affected device to reload and resulting in a denial of service condition. No authentication is required to exploit this vulnerability, significantly lowering the barrier for attackers. The vulnerability is tracked as CVE-2026-20212 and is currently awaiting full analysis by NVD. Cisco has published a security advisory with further details and remediation guidance.

Affected products

  • Cisco Nexus 9000 Series Switches
  • Silicon One integration

Related CVE's

  • CVE-2026-20212

Categories

  • Critical Infrastructure
  • Network Infrastructure
  • Zero-Day Vulnerabilities