Database/Firmware, BMC & network fabric
Cisco NX-OS: improper neutralization of input gives an authenticated low-privilege user full device compromise
Impact
A user who can already authenticate to the switch with low privileges escalates to full confidentiality, integrity and availability impact on the device (CVSS 8.8, PR:L). That turns a read-only or operator network account - the kind handed to monitoring, automation and NOC staff, and often shared via a service credential in a config management repo - into effective control of a leaf or spine carrying several tenants' traffic. Cisco found this in an internal hardening review and published no mechanism, so the affected CLI or API surface is unknown.
Who can reach it
Any user holding valid low-privilege credentials on an affected NX-OS device, over the network. Authentication is required; no user interaction. Includes automation and monitoring accounts.
What to do
Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch, so plan a window per device with traffic moved to the redundant peer. In the meantime, audit which accounts hold NX-OS login - especially shared automation credentials - and remove any that do not need it.
References
Related entries
- Cisco NX-OS: out-of-bounds write lets an authenticated user take over the switchCVE-2026-76459 · Cisco NX-OS Software (out-of-bounds write, also ACI mode and UCS Managed)High
- IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesCVE-2026-7868 · IBM OpenBMC (Power S1122/S1124 service processor firmware, ReadOnly role)High
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-006-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-012-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedNCVD-2022-001-infiniband-roce-local-rnic-kerne · InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processesHigh
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsCVE-2023-20514 · AMD Secure Processor - TEE parameter handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.