GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRF

CVE-2026-20212Firmware, BMC & network fabriccurated

Impact

TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF, and crafted input sent to them is executed as code with root privileges on the switch. Nexus 9000 boxes are the leaf/spine and storage-frontend fabric under most GPU fleets, so root on one gives an attacker a position that sees or reshapes east-west traffic between tenants, including RoCE and storage paths that were never expected to be attacker-observable. The same input can instead crash the S1HAL process and reload the device; a reload of a leaf takes every GPU node hanging off it out of the collective at once, which fails long-running distributed training jobs rather than just degrading them. No authentication is required, so exposure is decided entirely by who can route packets to the switch's L3 addresses.

Who can reach it

Anyone who can send TCP to ports 43210/43211 on an address the switch answers in the default L3 VRF. No authentication and no user interaction are required. In practice this means anyone on a network segment that reaches switch L3 interfaces, which on many fabrics includes tenant-facing subnets rather than only the management VLAN.

What to do

Move to a fixed NX-OS release per the Cisco advisory - the image swap takes the switch out of service for a reload, so it needs a maintenance window per device, or a pair-at-a-time rollout if the fabric is redundant. Until then, restrict reachability of TCP 43210 and 43211 with control-plane ACLs or by keeping switch L3 interfaces off tenant-reachable subnets. The record does not name the fixed version; read the Cisco advisory for the release matrix.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.