PT-2026-107609 · Cisco · Nx-Os
CVE-2026-76471
·
Published
2026-10-07
·
Updated
2026-10-08
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS Software (affected versions not specified)
Description
Insufficient input validation in the NX-API feature allows an unauthenticated remote attacker to execute arbitrary code with root privileges or trigger a denial of service (DoS) condition. This is achieved by sending a crafted HTTP request to the NX-API. Successful exploitation may lead to process crashes, resulting in a device reload.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nx-Os