CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/43211
Cisco patches an unauthenticated path to root code execution on Nexus 9000 switches carrying a Silicon One ASIC
Defender actions
- Run
show moduleon every Nexus 9000 switch to identify units carrying a Silicon One ASIC (PIDs N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O/Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804/9808); upgrade those to a fixed NX-OS release via Cisco's Software Checker, and until upgraded, deploy an infrastructure ACL denying TCP destined to ports 43210/43211 or Cisco's Live Protect shield for CVE-2026-20212.
Analysis
Cisco published cisco-sa-n9k-s1-rce-EH8dEtr on 2026-09-02, disclosing CVE-2026-20212 (CVSS 9.8, CWE-1327 Binding to an Unrestricted IP Address) in the Silicon One ASIC integration on Nexus 9000 Series switches. TCP ports 43210 and 43211, used by the S1HAL (Silicon One Hardware Abstraction Layer) process, are reachable in the default Layer 3 VRF; an unauthenticated remote attacker who can reach either port sends crafted input that executes as root, or crashes the S1HAL process and forces the device to reload (Cisco PSIRT, 2026-09-02). Only switches carrying a Silicon One ASIC are affected, Cisco names ten specific product IDs, determinable via show module; the advisory's own "Products Confirmed Not Vulnerable" section explicitly excludes the Nexus 3000 Series and every other Nexus 9000 model, which matters because MITRE's CVE record carries the broader title "Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability" (MITRE CVE Program, 2026-09-02). Cisco found the flaw during an internal TAC support case and states it is not aware of any public announcement or malicious use.
Fixed NX-OS software is available via Cisco's Software Checker. Until upgraded, Cisco recommends infrastructure ACLs (iACLs) denying TCP traffic destined to ports 43210/43211, or its temporary NX-OS "Live Protect" shield for this CVE, Cisco itself frames Live Protect as a bridge to patching, not a substitute for it. The same CERT-FR advisory (CERTFR-2026-AVI-1110) also bundled two lower-severity companion Cisco advisories from the same release cycle: an IOS XR hardening advisory covering several configuration-dependent weaknesses across multiple software trains, and a denial-of-service flaw in the SIP software running on several Cisco IP Phone and Wireless IP Phone models.
Cited evidence
This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges.
The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.