Executive brief
Cisco Nexus 9000 Series Switches with Silicon One ASICs are vulnerable to unauthenticated remote code execution via exposed network management ports. An attacker can connect to TCP ports 43210 or 43211 and execute arbitrary code with root privileges, potentially causing device crashes and network outages. This affects multiple switch models commonly deployed in enterprise data center and campus networks.
Technical details
This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF) environment without authentication. An unauthenticated, network-adjacent attacker can connect to these exposed ports and send specially crafted input that is executed with root privileges. The root cause is improper access control on the Silicon One Hardware Abstraction Layer (S1HAL) process, which handles communication on these ports. Successful exploitation allows code execution with the highest system privileges; exploitation can also crash the S1HAL process, triggering a device reload and service interruption. Cisco has released software updates and provides Live Protect temporary shields as interim mitigations.
Affected products
- Cisco Nexus 9000 Series Switches Multiple versions affected; see Cisco Software Checker for specific vulnerable releases
Timeline
- 2026-09-02: disclosed: Cisco Security Advisory published