---
schema: 1
kind: vulnerability
title: "CVE-2026-20212 — Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/43211"
headline: "Cisco patches an unauthenticated path to root code execution on Nexus 9000 switches carrying a Silicon One ASIC"
summary: >
  Cisco's cisco-sa-n9k-s1-rce-EH8dEtr (2026-09-02) fixes CVE-2026-20212 (CVSS 9.8), a flaw reachable
  because TCP ports 43210/43211 used by the Silicon One Hardware Abstraction Layer (S1HAL) process
  are exposed in the default Layer 3 VRF on ten named Nexus 9000 product IDs. An unauthenticated
  network attacker who reaches either port can execute code as root or crash the device. Found
  internally by Cisco; no known exploitation.
discovered_at: "2026-09-04T05:10:00Z"
updated_at: null
event_date: "2026-09-02"
run_id: 2026-09-04T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, patch-available]
regions: [global]
sectors: [public-sector]
entities: []
techniques: [T1190]
affected_products: ["Cisco Nexus 9000 Series Switches"]
cves:
  - id: CVE-2026-20212
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Nexus 9000 Series Switches carrying a Silicon One ASIC (PIDs N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808) — see Cisco's own advisory for the affected-release table"
    fixed: "Fixed NX-OS release per Cisco Software Checker"
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr"
    publisher: "Cisco PSIRT"
    date: "2026-09-02"
    role: primary
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0338"
    publisher: "NCSC-NL"
    date: "2026-09-03"
    role: corroborating
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1110/"
    publisher: "CERT-FR / ANSSI"
    date: "2026-09-03"
    role: corroborating
  - url: "https://cveawg.mitre.org/api/cve/CVE-2026-20212"
    publisher: "MITRE CVE Program"
    date: "2026-09-02"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges."
    publisher: "Cisco PSIRT"
  - quote: "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
    publisher: "Cisco PSIRT"
verification: single-source
sourcing_note: >
  Cisco PSIRT is the primary disclosing party for its own product (Admiralty vendor-PSIRT
  carve-out). NCSC-NL and CERT-FR both relay the same Cisco bulletin the same publication cycle
  rather than independently assessing it, so credibility stays at 2 rather than 1. MITRE's CVE
  record title names "Nexus 3000 and 9000 Series" but Cisco's own advisory body explicitly lists
  the Nexus 3000 Series and all other Nexus 9000 models under "Products Confirmed Not Vulnerable" —
  the advisory's affected-products list, not the CVE title, is authoritative here.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Run `show module` on every Nexus 9000 switch to identify units carrying a Silicon One ASIC (PIDs N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O/Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804/9808); upgrade those to a fixed NX-OS release via Cisco's Software Checker, and until upgraded, deploy an infrastructure ACL denying TCP destined to ports 43210/43211 or Cisco's Live Protect shield for CVE-2026-20212."
updates: []
migrated_from: null
---

Cisco published cisco-sa-n9k-s1-rce-EH8dEtr on 2026-09-02, disclosing CVE-2026-20212 (CVSS 9.8, CWE-1327 Binding to an Unrestricted IP Address) in the Silicon One ASIC integration on Nexus 9000 Series switches. TCP ports 43210 and 43211, used by the S1HAL (Silicon One Hardware Abstraction Layer) process, are reachable in the default Layer 3 VRF; an unauthenticated remote attacker who can reach either port sends crafted input that executes as root, or crashes the S1HAL process and forces the device to reload ([Cisco PSIRT, 2026-09-02](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr)). Only switches carrying a Silicon One ASIC are affected — Cisco names ten specific product IDs, determinable via `show module`; the advisory's own "Products Confirmed Not Vulnerable" section explicitly excludes the Nexus 3000 Series and every other Nexus 9000 model, which matters because MITRE's CVE record carries the broader title "Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability" ([MITRE CVE Program, 2026-09-02](https://cveawg.mitre.org/api/cve/CVE-2026-20212)). Cisco found the flaw during an internal TAC support case and states it is not aware of any public announcement or malicious use.

Fixed NX-OS software is available via Cisco's Software Checker. Until upgraded, Cisco recommends infrastructure ACLs (iACLs) denying TCP traffic destined to ports 43210/43211, or its temporary NX-OS "Live Protect" shield for this CVE — Cisco itself frames Live Protect as a bridge to patching, not a substitute for it. The same CERT-FR advisory (CERTFR-2026-AVI-1110) also bundled two lower-severity companion Cisco advisories from the same release cycle: an IOS XR hardening advisory covering several configuration-dependent weaknesses across multiple software trains, and a denial-of-service flaw in the SIP software running on several Cisco IP Phone and Wireless IP Phone models.

**Defender takeaway:** an unauthenticated root-RCE primitive on core network-fabric switching hardware demands patching or the iACL workaround ahead of the normal maintenance window, not on it — S1HAL sits in the data-center switch's own control path, so a successful exploit compromises the fabric itself, not an endpoint behind it. Detection concept: monitor for inbound TCP SYN or connection attempts to 43210/43211 on any Nexus 9000 management or control-plane VRF interface from unexpected sources — these ports have no legitimate business reason to be reached from outside the switch's own internal S1HAL control path.
