PT-2019-2448 · Cisco+1 · Cisco Nx-Os+3
Published
2019-05-15
·
Updated
2023-04-20
·
CVE-2019-1795
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco FXOS Software versions (affected versions not specified)
Cisco NX-OS Software versions (affected versions not specified)
Description
The issue is related to insufficient validation of input data in the command-line interface (CLI) of Cisco NX-OS and FX-OS, which could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. An attacker could exploit this by including malicious input as an argument of an affected command, potentially allowing the execution of arbitrary commands with elevated privileges. The attacker would need valid administrator credentials to exploit this.
Recommendations
For Cisco FXOS Software, update to a version that includes the fix for this issue.
For Cisco NX-OS Software, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the CLI command that is vulnerable to malicious input until a patch is available.
Fix
Command Injection
RCE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Fxos
Cisco Nx-Os
Cisco Nexus
Linux