PT-2017-12506 · Cisco · Cisco Nx-Os System+1
Published
2017-11-29
·
Updated
2019-10-03
·
CVE-2017-12340
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS System Software (affected versions not specified)
Description
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The issue is due to insufficient sanitization of user-supplied parameters passed to certain functions of the Python scripting sandbox. An attacker could exploit this vulnerability to escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the authenticated user. To exploit this vulnerability, the attacker must have local access to the affected system and be authenticated to the affected system with administrative or Python execution privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nx-Os System
Cisco Nexus