Cisco Security Advisory - Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability

Started by Netwörkheäd, May 23, 2021, 06:06:02 AM

Previous topic - Next topic

Netwörkheäd

Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API.


The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability. 


Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-cli-bypass



     
         
Security Impact Rating:  Medium
   
   
       
CVE: CVE-2019-1726
Source: Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Let's not argue. Let's network!