Skip to content

CVE-2026-20212

Cisco Nexus 3000 and 9000 Series Switches Silicon One HAL remote code execution (CVE-2026-20212)

Critical 9.8 Vendor: Cisco Published

Cisco NX-OS for Nexus 3000/9000 exposes TCP ports 43210 and 43211 in the default L3 VRF, allowing unauthenticated remote code execution with root privileges. CVSS 9.8 critical. Apply Cisco's fix and use iACLs as a workaround.

What happened

An unauthenticated remote attacker can reach TCP ports 43210 and 43211 on the default Layer 3 virtual routing and forwarding (VRF) of an affected Cisco NX-OS device. By connecting to the device and sending crafted input, the attacker could execute code with root privileges. A successful exploit could also crash the Silicon One Hardware Abstraction Layer (S1HAL) process and cause the device to reload.

The vulnerability is network-exploitable with low attack complexity, requires no privileges and no user interaction, and has high impact on confidentiality, integrity and availability. Cisco rates it critical with a CVSS 3.1 score of 9.8.

Cisco PSIRT states that it is not aware of any public announcements or malicious use of the vulnerability, and there is no recorded public disclosure.

Who is affected

Affected software is Cisco NX-OS Software, specifically versions 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(99w), 10.3(3w), 10.3(99x) and 10.3(3o). The issue relates to the Silicon One integration for Cisco Nexus 9000 Series Switches, and the CVE title also names Nexus 3000 Series Switches.

The affected ports are reachable in the default L3 VRF, so devices whose control plane is reachable over untrusted networks are the most exposed. Cisco's advisory should be checked for the fixed release applicable to each affected track.

What to do now

  1. Apply the fixed release identified in Cisco's advisory for each affected NX-OS track. Cisco indicates that a fix is available.
  2. Until patching is complete, implement infrastructure access control lists (iACLs) to allow only required management and control plane traffic destined to the affected device.
  3. Alternatively, use iACLs to explicitly deny all TCP packets destined to a locally configured IP address with a destination port of 43210 or 43211.
  4. Validate the iACL in a test environment before production use. Cisco notes that the workaround may affect functionality or performance depending on the deployment.

How to detect it

Start with exposure: confirm that no untrusted network can reach TCP ports 43210 or 43211 on affected switches in the default L3 VRF. Monitor for unexpected S1HAL process crashes or unplanned device reloads, which Cisco describes as a possible consequence of exploitation. Cisco has not published specific indicators of compromise for this vulnerability.

Beyond the patch

Beyond the patch, this is a control-plane exposure problem: two specific ports reachable in a default VRF are exactly what a continuous exposure management process should flag before exploitation. Spirity's Virtual CISO Services can put that visibility in place, and if code execution does occur, Managed Detection & Response can detect the subsequent activity.

Affected and fixed versions

ProductAffectedFixed in
Cisco NX-OS Software10.3(1)
10.3(2)
10.3(3)
10.4(1)
10.3(99w)
10.3(3w)
10.3(99x)
10.3(3o)
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.