Command Injection Vulnerability in Cisco NX-OS Software
CVE-2018-0307

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 June 2018

Summary

A command injection vulnerability exists within the command-line interface (CLI) of Cisco NX-OS Software. This flaw allows an authenticated local attacker to exploit insufficient input validation of command arguments. By injecting malicious arguments into vulnerable CLI commands, an attacker, already possessing privileged user access, could execute arbitrary commands with root-level privileges on the affected device. Additionally, in environments supporting multiple virtual device contexts (VDC), this vulnerability might enable unauthorized access to files across any VDC. Affected products include a range of Nexus Series switches, highlighting the need for prompt security reviews and risk assessments.

Affected Version(s)

Cisco NX-OS unknown Cisco NX-OS unknown

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.