Role-Based Access Vulnerability in Cisco NX-OS Software
CVE-2018-0337

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 June 2018

Summary

A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software allows an authenticated, local attacker to execute arbitrary commands on the device. This security flaw arises from inadequate input and validation checks for specific file systems. By issuing specially crafted commands through the command-line interface, an attacker could exploit this vulnerability and potentially compel other users to execute unintended commands, compromising the integrity of the system.

Affected Version(s)

Cisco NX-OS unknown Cisco NX-OS unknown

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.