Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

A security weakness in certain Cisco Nexus 9000 Series Switches lets an attacker connect remotely without needing to log in and run harmful commands with full admin rights. This happens because specific network ports (43210 and 43211) are open by default, letting attackers send malicious data. Exploiting this could also crash a key process, forcing the device to restart. Cisco has published software updates and workarounds to protect devices.

Published 2/9/2026, 4:00:00 pmVerified 3/9/2026, 4:17:40 amRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

A security weakness in certain Cisco Nexus 9000 Series Switches lets an attacker connect remotely without needing to log in and run harmful commands with full admin rights. This happens because specific network ports (43210 and 43211) are open by default, letting attackers send malicious data. Exploiting this could also crash a key process, forcing the device to restart. Cisco has published software updates and workarounds to protect devices.

Technical explanation

How the issue affects the environment

Cisco Nexus 9000 Series Switches with Silicon One ASICs expose TCP ports 43210 and 43211 in the default Layer 3 VRF, permitting unauthenticated remote access. An attacker can exploit this by sending crafted inputs through these accessible ports, enabling arbitrary code execution with root privileges. Additionally, exploitation can cause the S1HAL process to crash, potentially triggering device reloads. Cisco's updates address this vulnerability by restricting access and input handling, complemented by infrastructure ACLs as temporary mitigation.

Operational impact

Why teams should care

Successful exploitation grants attackers root-level control over affected switches, risking network compromise, data breaches, and service disruptions due to device crashes and reloads. This elevates the criticality for affected enterprise networks relying on these switches for core routing and switching functions.

Immediate action

Cisco strongly recommends upgrading to the fixed software releases specified in their advisory, which correct the vulnerability. Until then, implementing infrastructure access control lists (iACLs) to restrict or block TCP traffic on ports 43210 and 43211 to the affected devices can mitigate risk. Cisco also provides a Live Protect shield as a temporary mitigation measure.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

Use infrastructure access control lists (iACLs) to restrict management and control plane traffic to only necessary flows or explicitly deny all TCP packets destined for ports 43210 and 43211 on the affected devices' local IP addresses. Customers should evaluate the applicability and impact of these iACLs within their environment before deployment.

Evidence and validation checklist

  • Cisco PSIRT advisory confirming vulnerability in Silicon One integration on Nexus 9000 Series Switches
  • Accessibility of TCP ports 43210 and 43211 in default Layer 3 VRF as attack vector
  • Potential for unauthenticated remote code execution with root privileges
  • Possible crash of the S1HAL process leading to device reloads
  • Confirmed presence of workarounds using infrastructure ACLs
  • Release of software updates addressing the vulnerability
  • Absence of public exploitation or malicious use reports

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source