QID 317211
Date Published: 2022-07-21
QID 317211: Cisco Nexus Dashboard Multiple Vulnerabilities (cisco-sa-ndb-mprvesc-EMhDgXe5)
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device.
Affected Products:
Cisco Nexus Dashboard (Cisco APIC)
Cisco APIC Version 1.1
Cisco APIC Version 2.0
Cisco APIC Version 2.1
Cisco APIC Version 2.2 Prior to 2.2(1e)
Note: Cisco APIC Version 1.1
Only affected by CVE-2022-20909
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
An attacker could exploit these vulnerabilities by authenticating as the rescue-user and executing vulnerable CLI commands using a malicious payload. A successful exploit could allow the attacker to elevate privileges to root on an affected device.
Customers are advised to refer to cisco-sa-ndb-mprvesc-EMhDgXe5 for more information.
- cisco-sa-ndb-mprvesc-EMhDgXe5 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndb-mprvesc-EMhDgXe5
CVEs related to QID 317211
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ndb-mprvesc-EMhDgXe5 |
|