CTIPilot

Cisco Nexus 9000 Series Silicon One S1HAL unauthenticated root RCE (CVSS 9.8)

cve · CVE-2026-20212 single-source

Coverage timeline
1
first 2026-09-04 → last 2026-09-04
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-04/cve-2026-20212-cisco-nexus-9000-s1hal-unauth-root-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-04CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/43211
    trending-vulnerabilitiesCisco patches an unauthenticated path to root code execution on Nexus 9000 switches carrying a Silicon One ASIC

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (25%)
  • cert.ssi.gouv.fr1 (25%)
  • cveawg.mitre.org1 (25%)
  • sec.cloudapps.cisco.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Cisco Nexus 9000 Series Silicon One S1HAL unauthenticated root RCE (CVSS 9.8) (1)

2026-09-04 · view entry permalink →

HIGHCVE-2026-20212NATOA2

CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/43211

Cisco published cisco-sa-n9k-s1-rce-EH8dEtr on 2026-09-02, disclosing CVE-2026-20212 (CVSS 9.8, CWE-1327 Binding to an Unrestricted IP Address) in the Silicon One ASIC integration on Nexus 9000 Series switches. TCP ports 43210 and 43211, used by the S1HAL (Silicon One Hardware Abstraction Layer) process, are reachable in the default Layer 3 VRF; an unauthenticated remote attacker who can reach either port sends crafted input that executes as root, or crashes the S1HAL process and forces the device to reload (Cisco PSIRT, 2026-09-02). Only switches carrying a Silicon One ASIC are affected, Cisco names ten specific product IDs, determinable via show module; the advisory's own "Products Confirmed Not Vulnerable" section explicitly excludes the Nexus 3000 Series and every other Nexus 9000 model, which matters because MITRE's CVE record carries the broader title "Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability" (MITRE CVE Program, 2026-09-02). Cisco found the flaw during an internal TAC support case and states it is not aware of any public announcement or malicious use.

Fixed NX-OS software is available via Cisco's Software Checker. Until upgraded, Cisco recommends infrastructure ACLs (iACLs) denying TCP traffic destined to ports 43210/43211, or its temporary NX-OS "Live Protect" shield for this CVE, Cisco itself frames Live Protect as a bridge to patching, not a substitute for it. The same CERT-FR advisory (CERTFR-2026-AVI-1110) also bundled two lower-severity companion Cisco advisories from the same release cycle: an IOS XR hardening advisory covering several configuration-dependent weaknesses across multiple software trains, and a denial-of-service flaw in the SIP software running on several Cisco IP Phone and Wireless IP Phone models.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges.

The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

Cisco PSIRT 2026-09-02
vulnerability04 Sep 05:10Zsingle-sourceOpen finding ↗