Command Injection Vulnerability in Cisco NX-OS Software
CVE-2018-0307
Summary
A command injection vulnerability exists within the command-line interface (CLI) of Cisco NX-OS Software. This flaw allows an authenticated local attacker to exploit insufficient input validation of command arguments. By injecting malicious arguments into vulnerable CLI commands, an attacker, already possessing privileged user access, could execute arbitrary commands with root-level privileges on the affected device. Additionally, in environments supporting multiple virtual device contexts (VDC), this vulnerability might enable unauthorized access to files across any VDC. Affected products include a range of Nexus Series switches, highlighting the need for prompt security reviews and risk assessments.
Affected Version(s)
Cisco NX-OS unknown Cisco NX-OS unknown
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved