PT-2019-2448 · Cisco+1 · Cisco Nx-Os+3

Publicado

2019-05-15

·

Atualizado

2023-04-20

·

CVE-2019-1795

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software versions (affected versions not specified) Cisco NX-OS Software versions (affected versions not specified)
Description The issue is related to insufficient validation of input data in the command-line interface (CLI) of Cisco NX-OS and FX-OS, which could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. An attacker could exploit this by including malicious input as an argument of an affected command, potentially allowing the execution of arbitrary commands with elevated privileges. The attacker would need valid administrator credentials to exploit this.
Recommendations For Cisco FXOS Software, update to a version that includes the fix for this issue. For Cisco NX-OS Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI command that is vulnerable to malicious input until a patch is available.

Correção

Command Injection

RCE

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02226
CVE-2019-1795

Produtos afetados

Cisco Fxos
Cisco Nx-Os
Cisco Nexus
Linux