rootpwn

Vulnerabilities

Critical RCE in Cisco Nexus 9000 Silicon One – Unauthenticated Remote Code Execution via Open Ports 43210/43211

Cisco has disclosed a critical remote code execution flaw in the Silicon One integration on its Nexus 9000 Series switches. The vulnerability, CVE‑2026‑20212, exposes TCP ports 43210 and 43211 in the default L3 VRF, allowing any unauthenticated attacker to send crafted packets that execute as root and can even crash the S1HAL process, forcing a device reload. Cisco has issued patches and workarounds; administrators should update immediately to mitigate the risk.

A newly identified flaw in Cisco’s Nexus 9000 Series switches’ Silicon One integration enables remote attackers to execute arbitrary code with root privileges. The weakness stems from two TCP ports—43210 and 43211—that remain open in the default Layer 3 virtual routing and forwarding (VRF) configuration.

How the Attack Works

By connecting to either of the exposed ports, an attacker can send specially crafted input that is interpreted as executable code. If the exploit succeeds, the attacker gains full root access to the switch. Additionally, the S1HAL process may crash, causing the device to reboot—potentially disrupting network operations.

Impact and Severity

  • Unauthenticated, remote exploitation possible.
  • Full root privileges granted to the attacker.
  • Potential for device reload via S1HAL crash.
  • Critical severity (Cisco Security Impact Rating: Critical).

Mitigation Steps

  • Apply the latest Cisco software updates that address CVE‑2026‑20212.
  • Implement the available workarounds if immediate patching is not feasible.
  • Restrict or close TCP ports 43210 and 43211 on the affected devices.
  • Verify that the default L3 VRF configuration no longer exposes these ports.
Administrators should act swiftly—patching or disabling the vulnerable ports—to prevent potential compromise of critical network infrastructure.

Cisco Nexus9000 Remote Code Execution CVE-2026-20212 Critical Vulnerability

← All news