PT-2017-12506 · Cisco · Cisco Nx-Os System+1

Published

2017-11-29

·

Updated

2019-10-03

·

CVE-2017-12340

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco NX-OS System Software (affected versions not specified)
Description A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The issue is due to insufficient sanitization of user-supplied parameters passed to certain functions of the Python scripting sandbox. An attacker could exploit this vulnerability to escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the authenticated user. To exploit this vulnerability, the attacker must have local access to the affected system and be authenticated to the affected system with administrative or Python execution privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12340

Affected Products

Cisco Nx-Os System
Cisco Nexus