PT-2017-12499 · Cisco · Cisco Nx-Os System+1

Publicado

2017-11-29

·

Atualizado

2017-12-15

·

CVE-2017-12332

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco NX-OS System Software (affected versions not specified)
Description A vulnerability in the patch installation process of Cisco NX-OS System Software could allow an authenticated, local attacker to write a file to arbitrary locations. This is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing a crafted patch image on an affected device. The vulnerable operation occurs prior to patch activation, and an exploit could allow the attacker to write arbitrary files on an affected system as root. The attacker would need valid administrator credentials to perform this exploit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12332

Produtos afetados

Cisco Nx-Os System
Cisco Nexus