【資安漏洞預警】Cisco 旗下 Nexus 9000系列交換器存在重大資安漏洞(CVE-2026-20212)
【Security Vulnerability Alert】Cisco Nexus 9000 Series Switches Contain a Major Security Vulnerability(CVE-2026-20212)

發布單位:圖資處網路系統組
日期範圍:2026/9/15 ~ 2027/3/15
 
發布單位:圖資處網路系統組
日期範圍:2026/9/15 ~ 2027/3/15
行政 行政公告
全體

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202609-00000003

[內容說明]
Cisco 針對旗下Nexus 9000系列交換器發布重大資安漏洞公告(CVE-2026-20212,CVSS:9.8),Cisco Nexus 9000 系列交換器的 Silicon One 整合存在漏洞,可能允許未經身份驗證的遠端攻擊者以root權限執行程式碼。

[影響平台]
N9324C-SE1U、 N9348Y2C6D-SE1U、 N9364E-SG2-O、 N9364E-SG2-Q、 N9396T12C-SE1、 N9348Y12C-SE1、 N9396Y12C-SE1、 N9336C-SE1、 N9K-C9804、 N9K-C9808

[建議措施]
根據官方網站釋出的解決方式進行修補

[參考資料]
1. https://www.twcert.org.tw/tw/cp-169-11185-7d481-1.html

Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert TWCERTCC-200-202609-00000003

[Content Description]
Cisco has released a major security vulnerability advisory for its Nexus 9000 Series switches(CVE-2026-20212,CVSS:9.8). A vulnerability exists in the Silicon One integration of Cisco Nexus 9000 Series switches, which may allow unauthenticated remote attackers to execute code with root privileges.

[Affected Platforms]
N9324C-SE1U、 N9348Y2C6D-SE1U、 N9364E-SG2-O、 N9364E-SG2-Q、 N9396T12C-SE1、 N9348Y12C-SE1、 N9396Y12C-SE1、 N9336C-SE1、 N9K-C9804、 N9K-C9808

[Recommended Measures]
Apply patches according to the solution released on the official website

[References]
1. https://www.twcert.org.tw/tw/cp-169-11185-7d481-1.html


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
system_update_alt參考資料
Top↑