Junglewise Threat Intelligence

CVE-2026-20212: Cisco Nexus 9000 Series Switches remote code execution in Silicon One integration

CVE-2026-20212 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Vendors: Cisco.

Executive brief

Cisco Nexus 9000 Series Switches with Silicon One ASICs are vulnerable to unauthenticated remote code execution via exposed network management ports. An attacker can connect to TCP ports 43210 or 43211 and execute arbitrary code with root privileges, potentially causing device crashes and network outages. This affects multiple switch models commonly deployed in enterprise data center and campus networks.

Technical details

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF) environment without authentication. An unauthenticated, network-adjacent attacker can connect to these exposed ports and send specially crafted input that is executed with root privileges. The root cause is improper access control on the Silicon One Hardware Abstraction Layer (S1HAL) process, which handles communication on these ports. Successful exploitation allows code execution with the highest system privileges; exploitation can also crash the S1HAL process, triggering a device reload and service interruption. Cisco has released software updates and provides Live Protect temporary shields as interim mitigations.

Affected products

  • Cisco Nexus 9000 Series Switches Multiple versions affected; see Cisco Software Checker for specific vulnerable releases

Timeline

  • 2026-09-02: disclosed: Cisco Security Advisory published

References