Security & Risk6 minNewsroom

Cisco Discloses 9.8 Vulnerability in Nexus 9000: Open TCP 43210 in Default VRF Allows RCE as Root

Corredor frio de data center com racks Cisco Nexus iluminados por LEDs, técnico ao fundo com notebook.

Advisory cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, affects switches N9K-C9804, N9K-C9808, and eight other references. Data center fabric needs to apply a patch or close the port.

Cisco published advisory cisco-sa-n9k-s1-rce-EH8dEtr on September 2, cataloged as CVE-2026-20212, describing a remote code execution vulnerability as root in the Silicon One integration of Nexus 9000 switches. The CVSS 3.1 score is 9.8, near the maximum, with the attack vector being the most serious possible for fabric equipment: an unauthenticated remote attacker can send a TCP payload against the device and gain privileged shell access.


The technical trigger is simple and thus concerning. TCP ports 43210 and 43211, used by the S1HAL management process of Silicon One, are accessible by default on the primary L3 VRF, the same in which most operators expose management interfaces. A malformed input packet executes as privileged code; if it fails to execute, it still crashes the S1HAL process and forces a switch reload. In other words, the same bug offers two attack vectors: total compromise or denial of service, the adversary's choice.


Scope of Affected Devices


Cisco listed ten affected product identifiers: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, in addition to modular chassis N9K-C9804 and N9K-C9808. The cut is not accidental: these are the Silicon One generations that replaced previous ASICs in recent high-density fabric rollouts. Those who updated their data center core in the last eighteen months are highly likely to be exposed.


Cisco released software updates and temporary mitigations on the same day. Where the patch cannot be applied immediately, the implicit recommendation is to close ports 43210 and 43211 on the management VRF via access control list at the perimeter infrastructure. This is not trivial in data center fabric, as these ports are often used by internal observability systems; any blind ACL can disrupt operational telemetry.


Where the Impact Will Be Felt


The Nexus 9000 serves as the backbone of fabric on three fronts that concentrate risk. In North American cloud providers, chassis N9K-C9804 and N9K-C9808 are present at the spine level in low-density AWS, Azure, and Google Cloud regions, as well as in nearly all installations of neutral operators like Equinix and Digital Realty. A root shell on a spine provides lateral access to the entire VXLAN overlay that passes through it. In European banks (Deutsche Bank, ING, BNP Paribas reported Cisco deployments in the core fabric in recent cycles), the patching timeline is regulated by a maintenance window agreed upon with the national financial authority, which may push remediation to December. In Asian operators, especially KDDI and SoftBank, the Silicon One fleet is more recent, which reduces exposure to legacy models but increases exposure to the listed SKUs.


Brazil appears indirectly affected. Colocation operators serving national financial institutions purchased N9K-C9808 during recent server room expansion cycles, and regional cloud providers have N9364E at the aggregation layer. The practical response is the same as in Europe: coordinated maintenance windows, perimeter mitigation ACL until the patch can be applied in production.


No Public Exploitation Yet, But Time Is Running Out


Until the advisory was published, Cisco did not indicate active exploitation in the wild. This is not a lasting comfort. CVE-2023-20198, also in Cisco networking products, was widely used within ten days after disclosure. The Nexus-specific CVE-2024-20399 was observed in state-sponsored campaigns within eight weeks. The historical pattern for the Nexus line is that automated scanners sweep TCP 43210 and similar ports in the early days, and a functional exploit appears in specialized blogs before the end of the month.


Changes in the Compliance Conversation


Operational security teams that still treated Silicon One as 'new ASIC, without a history of critical CVEs' need to recalibrate. This is the second 9.8 advisory in Cisco networking products in 2026, following the SD-WAN Manager in June. For the board, the implication is more budgetary than technical: a support contract that only covers a monthly maintenance window becomes unacceptable when the vector is accessible via the standard management port. Renegotiation of SLAs with the vendor, and not just patch application, will be the next demand from auditors.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk