808bits

Cisco Catalyst C4500X-32SFP+ and Catalyst C4500X-F-32SFP+

FIPS 140-2 certificate #1942 · Cisco Systems, Inc. · data as of 2026-09-03

Cisco Catalyst C4500X-32SFP+ and Catalyst C4500X-F-32SFP+, from Cisco Systems, Inc., holds FIPS 140-2 certificate #1942 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and when tamper evident labels and security devices are installed on the initially built configuration as indicated in the Security Policy

Certificate

Certificate number1942
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versionsCatalyst C4500X-32SFP+ and Catalyst C4500X-F-32SFP+; FIPS kit packaging (CVPN4500FIPS/KIT=)
Firmware versions3.3.1SG

Module description

Quoted from the NIST CMVP entry for this certificate.

The fixed-aggregation Cisco Catalyst 4500-X Series Switches deliver best-in-class scalability, simplified network virtualization, and integrated network services for space-constrained environments in campus networks. The Catalyst 4500-X switches provide a secure and manageable platform that meets FIPS 140-2 Level 2 requirements.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3

Approved algorithms (7)

AlgorithmCAVP certificates
AES1977
DRBG179
HMAC1190
RNG1072
RSA1023, 1024
SHS1730, 1731
Triple-DES1282

Other algorithms

MD4; MD5; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2013-05-02InitialSAIC-VA

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-05-02

Source documents