PT-2018-3547 · Cisco · Nexus 2000 Series Fabric Extenders+12
Published
2018-06-20
·
Updated
2020-09-04
·
CVE-2018-0307
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco NX-OS Software versions (affected versions not specified)
Description:
The issue is due to insufficient input validation of command arguments in the CLI of Cisco NX-OS Software, allowing an authenticated, local attacker to perform a command-injection attack. This could enable the attacker to execute arbitrary commands with root privileges. On products that support multiple virtual device contexts (VDC), this issue could also allow an attacker to access files from any VDC.
Recommendations:
For Nexus 2000 Series Fabric Extenders, update to a fixed software version.
For Nexus 3000 Series Switches, update to a fixed software version.
For Nexus 3500 Platform Switches, update to a fixed software version.
For Nexus 3600 Platform Switches, update to a fixed software version.
For Nexus 5500 Platform Switches, update to a fixed software version.
For Nexus 5600 Platform Switches, update to a fixed software version.
For Nexus 6000 Series Switches, update to a fixed software version.
For Nexus 7000 Series Switches, update to a fixed software version.
For Nexus 7700 Series Switches, update to a fixed software version.
For Nexus 9000 Series Switches in standalone NX-OS mode, update to a fixed software version.
For Nexus 9500 R-Series Line Cards and Fabric Modules, update to a fixed software version.
As a temporary workaround, consider restricting access to the CLI until a patch is available.
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus
Nexus 2000 Series Fabric Extenders
Nexus 3000 Series Switches
Nexus 3500 Platform Switches
Nexus 3600 Platform Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 7700 Series Switches
Nexus 9000 Series Switches
Nexus 9500 R-Series Line Cards/Fabric Modules