QID 317298
Date Published: 2023-03-27
QID 317298: Cisco Nexus Operating System (NX-OS) Software CLI Command Injection Vulnerability (cisco-sa-nxos-cli-cmdinject-euQVK9u)
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
Affected Products
MDS 9000 Series Multilayer Switches
Nexus 1000 Virtual Edge for VMware vSphere
Nexus 1000V Switch for Microsoft Hyper-V
Nexus 1000V Switch for VMware vSphere
Nexus 3000 Series Switches
Nexus 5500 Platform Switches
Nexus 5600 Platform Switches
Nexus 6000 Series Switches
Nexus 7000 Series Switches
Nexus 9000 Series Switches in standalone NX-OS mode
QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.
A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.
Customers are advised to refer to cisco-sa-nxos-cli-cmdinject-euQVK9u
- cisco-sa-nxos-cli-cmdinject-euQVK9u -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cli-cmdinject-euQVK9u
CVEs related to QID 317298
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-nxos-cli-cmdinject-euQVK9u |
|