QID 317136
Date Published: 2022-05-09
QID 317136: Cisco Nexus Operating System (NX-OS) Software NX-API Command Injection Vulnerability (cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2)
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco NX-OS Software and have the NX-API feature enabled:
Nexus 3000 Series Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.
A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
Customers are advised to refer to cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2 for more information.
- cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2
CVEs related to QID 317136
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2 |
|