PT-2019-2219 · Cisco · Cisco Nx-Os+1

Published

2019-05-15

·

Updated

2020-10-09

·

CVE-2019-1729

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software (affected versions not specified)
Description A vulnerability in the CLI implementation of a specific command used for image maintenance could allow an authenticated, local attacker to overwrite any file on the file system, including system files, at the root privilege level. This occurs due to the lack of verification of user-input parameters and digital-signature verification for image files when using a specific CLI command. An attacker could exploit this vulnerability by authenticating to the device and issuing a command at the CLI, potentially leading to a denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01990
CVE-2019-1729

Affected Products

Cisco Nx-Os
Cisco Nexus