Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Published May 15, 2019
7.8
HIGHCVSS 3.1
EPSS 0.41%
Description
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<6.2(25)
- Version unspecifiedStatusaffectedConstraints<7.0(3)I7(3)
- Version unspecifiedStatusaffectedConstraints<8.3(2)
- Version unspecifiedStatusaffectedConstraints<9.2(1)
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco NX-OS Software | n/a |
|
Configuration 1
Configuration 2
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
Running on/with
- n/a
- n/a
- n/a
- n/a
Configuration 4
Running on/with
- n/a
- n/a
- n/a
Configuration 5
Running on/with
- n/a
- n/a
Configuration 6
Running on/with
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://www.securityfocus.com/bid/108409 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-cli-bypass vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108409 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-cli-bypass | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.