Cisco NX-OS Software Bash Shell CVE-2019-1593 Local Privilege Escalation Vulnerability
BID:107324
CVE-2019-1593 |Info
Cisco NX-OS Software Bash Shell CVE-2019-1593 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 107324 |
| Class: | Design Error |
| CVE: |
CVE-2019-1593 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 06 2019 12:00AM |
| Updated: | Mar 06 2019 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco NX-OS 8.3 Cisco NX-OS 8.2 Cisco NX-OS 8.1 Cisco NX-OS 7.0(3)I7 Cisco NX-OS 7.0(3)I6 Cisco NX-OS 7.0(3)I5 Cisco NX-OS 7.0(3)I4 Cisco NX-OS 7.0(3) Cisco NX-OS 14.0 Cisco NX-OS 13.2 Cisco NX-OS 13.1 Cisco Nexus 9500 R-Series Line Cards and Fabric Modules 0 Cisco Nexus 9000 Series Switches in standalone NX-OS mode 0 Cisco Nexus 9000 Series Fabric Switches - ACI mode 0 Cisco Nexus 7700 Series Switches 0 Cisco Nexus 7000 Series Switches 0 Cisco Nexus 3600 Platform Switches 0 Cisco Nexus 3500 Platform Switches 0 Cisco Nexus 3000 Series Switches 0 |
| Not Vulnerable: |
Cisco NX-OS 8.2(3) Cisco NX-OS 7.0(3)I7(6) Cisco NX-OS 7.0(3)F3(5) Cisco NX-OS 14.0(3d) |
Discussion
Cisco NX-OS Software Bash Shell CVE-2019-1593 Local Privilege Escalation Vulnerability
Cisco NX-OS Software is prone to a local privilege-escalation vulnerability.
A local attacker may exploit this issue to gain elevated system privileges on the device.
This issue is being tracked by Cisco Bug IDs CSCvj59431, CSCvj59446, CSCvk52940, CSCvk52941.
Cisco NX-OS Software is prone to a local privilege-escalation vulnerability.
A local attacker may exploit this issue to gain elevated system privileges on the device.
This issue is being tracked by Cisco Bug IDs CSCvj59431, CSCvj59446, CSCvk52940, CSCvk52941.
Exploit / POC
Cisco NX-OS Software Bash Shell CVE-2019-1593 Local Privilege Escalation Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco NX-OS Software Bash Shell CVE-2019-1593 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.