BlackTree Security · Infrastructure · Automation · AI

A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches

Cisco has disclosed a critical Nexus 9000 flaw where a network packet can become root-level code on the switch. The vulnerable service is reachable through TCP ports 43210 and 43211 in the default Layer 3 VRF.

CVE-2026-20212 affects specific Nexus 9000 switches built with a Cisco Silicon One ASIC. An unauthenticated remote attacker can connect to an exposed service and send crafted input that executes with root privileges. Successful exploitation can also crash the S1HAL process and reload the device.

The dangerous part is the default network exposure

The problem is not a management page that an administrator must accidentally publish. Cisco says the two TCP ports are accessible in the default Layer 3 virtual routing and forwarding configuration. The network path itself becomes the security boundary.

Affected product identifiers include N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804 and N9K-C9808. Teams should verify the product identifier with show module instead of assuming every Nexus 9000 device is affected.

No exploitation is known, but the exposure is critical

Cisco published its advisory for CVE-2026-20212 on 2 September 2026 at 16:00 GMT. PSIRT said it was not aware of public announcements or malicious use at publication. Cisco found the flaw while resolving a Technical Assistance Center support case.

The combination of no authentication, low attack complexity and root impact makes this a high-priority exposure check even without a public exploit. Network teams should not wait for exploitation reports before closing the ports or applying the fixed software.

What defenders should do now

  • Run show module and compare the reported product identifier with Cisco’s affected-model list.
  • Use Cisco’s Software Checker to identify the first fixed release for the installed NX-OS train and upgrade to it.
  • Until the upgrade is complete, use infrastructure access control lists to deny unsolicited traffic to TCP ports 43210 and 43211 on locally configured addresses.
  • Deploy Cisco’s Live Protect shield where supported, treating it as a temporary bridge rather than a replacement for the software fix.
  • Review S1HAL crashes, unexpected reloads, configuration changes and traffic aimed at the two exposed ports.

The workaround has operational consequences

Cisco says the infrastructure ACL workaround was successful in its test environment, but warns that mitigations can affect functionality or performance. Teams should test the rule against required management and control-plane traffic before broad deployment.

A Live Protect shield is also available. Cisco still recommends installing fixed NX-OS software for complete remediation.

The bigger lesson

Switches are trusted because they sit beneath the application layer. That trust makes a root-level network service especially valuable to an attacker. A port open in the default routing context can quietly turn a forwarding device into a remote control point for the network itself.

Sources: Cisco’s Nexus 9000 Silicon One advisory, Cisco Live Protect shield release notes, and Cisco’s Nexus security-advisory index.

One comment

  1. This vulnerability highlights how exposed network services can become serious entry points for attackers. Strong access controls, timely patching, and careful network monitoring are essential to protect critical infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *