Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Arbitrary File Read Vulnerability
Published Mar 6, 2019
4.4
MEDIUMCVSS 3.1
EPSS 0.35%
Description
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).
Affected products
- Vendor Cisco Product Cisco NX-OS Software for Nexus 9000 Series Fabric Switches ACI Mode Defaultn/a
- Version unspecifiedStatusaffectedConstraints<14.0(1h)
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco NX-OS Software for Nexus 9000 Series Fabric Switches ACI Mode | n/a |
|
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://www.securityfocus.com/bid/107316 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-aci-file-read vendor-advisoryx_refsource_CISCOPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107316 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-aci-file-read | vendor-advisoryx_refsource_CISCOPatchVendor Advisory |
Change history (0)
No recorded changes yet.