Cisco Security Advisory - Cisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation Vulnerability

Started by Netwörkheäd, August 28, 2021, 06:02:12 AM

Previous topic - Next topic

Netwörkheäd

Cisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation Vulnerability

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device.


This vulnerability is due to insufficient restrictions during the execution of a specific CLI command. An attacker with administrative privileges could exploit this vulnerability by performing a command injection attack on the vulnerable command. A successful exploit could allow the attacker to access the underlying operating system as root


Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


This advisory is available at the following link: 
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-naci-mdvul-vrKVgNU



This advisory is part of the August 2021 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: August 2021 Cisco FXOS and NX-OS Software Security Advisory Bundled Publication.




     
         
Security Impact Rating:  Medium
   
   
       
CVE: CVE-2021-1584
Source: Cisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation Vulnerability
Let's not argue. Let's network!