Sceawere
Vulnerability Detail
CVE-2026-76471UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cisco NX-OS NX-API RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Cisco
- Product
- Cisco NX-OS Software
- Attack Type
- Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-07T17:17:00.230Z",
"pubdate": "2026-10-07T17:17:00.230Z",
"executiveSummary": "This vulnerability concerns an improper input validation flaw within the NX-API feature of Cisco NX-OS Software. The security defect allows an unauthenticated, remote attacker to gain unauthorized execution capabilities on the underlying system.\nThe primary impact of this vulnerability is Remote Code Execution (RCE) with elevated root privileges, providing an attacker complete control over the affected device. Additionally, the vulnerability can be leveraged to induce a Denial of Service (DoS) condition, resulting in application process instability and subsequent device reloads.\nThe vulnerability affects Cisco NX-OS Software deployments where the NX-API feature is enabled. Because the exploit vector involves the transmission of crafted HTTP requests to the exposed API endpoint, it poses a significant risk to network availability and data integrity.\nExploitation does not require prior authentication or elevated privileges, making it accessible to any remote attacker with network reach to the device's management interface. Given the potential for root-level command execution, this represents a critical risk to infrastructure security.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of user-supplied data transmitted to the NX-API interface. The NX-API serves as a programmatic interface for managing Cisco NX-OS devices via HTTP/HTTPS, typically utilizing JSON or XML payloads for configuration and operational command execution. The implementation fails to properly sanitize or constrain input parameters before processing them within the internal execution context.\nThe exploitation method involves an attacker crafting malicious HTTP requests directed at the affected NX-API endpoint. By injecting specifically formatted data payloads, an attacker can bypass existing security controls and manipulate internal system functions. Because the NX-API service operates with elevated permissions, the processed input can influence control flow, leading to arbitrary code execution within the context of the root user.\nThe attack flow proceeds as follows: First, the attacker identifies a network-reachable Cisco device with the NX-API feature enabled. Second, the attacker transmits a specially crafted HTTP request containing malicious input designed to trigger the validation logic failure. Third, upon receiving the request, the NX-API component parses the input, which triggers the vulnerability. Finally, the malicious payload is executed by the system, granting the attacker arbitrary code execution capabilities with root-level privileges or inducing memory corruption/process state errors that lead to a DoS condition.\nThe vulnerability resides within the request-processing logic of the NX-API module. When the system attempts to process the crafted request, the improper handling of the input data can result in an unexpected state. This state is either leveraged to divert execution to attacker-controlled memory regions (enabling RCE) or to force the service into an unrecoverable crash loop. If the crash involves critical system processes, the Cisco NX-OS watchdog or kernel integrity mechanisms may initiate a device reload, thereby fulfilling the DoS requirement.\nThis vulnerability is particularly severe due to the remote, unauthenticated nature of the attack vector. It requires no specific prior knowledge of the internal system state, only the ability to reach the HTTP(S) management service. Post-exploitation impact includes persistent unauthorized access, modification of device configurations, lateral movement within the network, and the disruption of critical networking services due to hardware reloads."
}