PT-2019-2448 · Cisco+1 · Cisco Nx-Os+3

Published

2019-05-15

·

Updated

2023-04-20

·

CVE-2019-1795

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco FXOS Software versions (affected versions not specified) Cisco NX-OS Software versions (affected versions not specified)
Description The issue is related to insufficient validation of input data in the command-line interface (CLI) of Cisco NX-OS and FX-OS, which could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. An attacker could exploit this by including malicious input as an argument of an affected command, potentially allowing the execution of arbitrary commands with elevated privileges. The attacker would need valid administrator credentials to exploit this.
Recommendations For Cisco FXOS Software, update to a version that includes the fix for this issue. For Cisco NX-OS Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI command that is vulnerable to malicious input until a patch is available.

Fix

Command Injection

RCE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02226
CVE-2019-1795

Affected Products

Cisco Fxos
Cisco Nx-Os
Cisco Nexus
Linux