CVE-2019-1776
15.05.2019, 20:29
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
| Vendor | Product | Version |
|---|---|---|
| cisco | nx-os | 𝑥 < 8.2\(2\) |
| cisco | nx-os | 8.3 ≤ 𝑥 < 8.3\(1\) |
| cisco | nx-os | 𝑥 < 7.0\(3\)i4\(9\) |
| cisco | nx-os | 7.0\(3\)i7 ≤ 𝑥 < 7.3\(3\)i7\(4\) |
| cisco | nx-os | 𝑥 < 6.0\(2\)a8\(11\) |
| cisco | nx-os | 7.0\(3\)i4 ≤ 𝑥 < 7.0\(3\)i4\(9\) |
| cisco | nx-os | 7.0\(3\)i7 ≤ 𝑥 < 7.3\(3\)i7\(4\) |
| cisco | nx-os | 7.0\(3\) ≤ 𝑥 < 7.0\(3\)f3\(5\) |
| cisco | nx-os | 𝑥 < 7.3\(5\)n1\(1\) |
| cisco | nx-os | 𝑥 < 7.3\(3\)d1\(1\) |
| cisco | nx-os | 8.0 ≤ 𝑥 < 8.2\(2\) |
| cisco | nx-os | 8.3 ≤ 𝑥 < 8.3\(1\) |
| cisco | nx-os | 𝑥 < 4.0\(1a\) |
𝑥
= Vulnerable software versions