PT-2019-1566 · Cisco+1 · Cisco Nx-Os+2

Published

2019-03-06

·

Updated

2020-10-08

·

CVE-2019-1596

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software versions prior to 7.0(3)I7(4) Cisco NX-OS Software versions prior to 7.0(3)F3(5)
Description A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with valid user credentials. The vulnerability is due to incorrect permissions of a system executable. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level to root.
Recommendations For versions prior to 7.0(3)I7(4), update to version 7.0(3)I7(4) or later. For versions prior to 7.0(3)F3(5), update to version 7.0(3)F3(5) or later. As a temporary workaround, consider restricting access to the Bash shell until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01097
CVE-2019-1596

Affected Products

Bash
Cisco Nx-Os
Cisco Nexus