Vulnslist

find the latest Cisco vulnerabilities

Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability

cisco-sa-20190515-nxos-cli-bypass · Medium · Published · Updated

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability.  Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-cli-bypass

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1726
Cisco Bug IDsCSCvh24771, CSCvi99251, CSCvi99248, CSCvi99247, CSCvi99252, CSCvn11851, CSCvi99250
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Computing System (Managed), Cisco NX-OS Software 6.0(1), Cisco NX-OS Software 6.0(2), Cisco NX-OS Software 6.0(3), Cisco NX-OS Software 6.0(4), Cisco NX-OS Software 6.0(2)A1(1), Cisco NX-OS Software 6.0(2)A1(1a), Cisco NX-OS Software 6.0(2)A1(1b), Cisco NX-OS Software 6.0(2)A1(1c), Cisco NX-OS Software 6.0(2)A1(1d), Cisco NX-OS Software 6.0(2)A1(1e), Cisco NX-OS Software 6.0(2)A1(1f), Cisco NX-OS Software 6.0(2)A1(2d), Cisco NX-OS Software 6.0(2)A3(1), Cisco NX-OS Software 6.0(2)A3(2), Cisco NX-OS Software 6.0(2)A3(4), Cisco NX-OS Software 6.0(2)A4(1), Cisco NX-OS Software 6.0(2)A4(2), Cisco NX-OS Software 6.0(2)A4(3), Cisco NX-OS Software 6.0(2)A4(4), Cisco NX-OS Software 6.0(2)A4(5), Cisco NX-OS Software 6.0(2)A4(6), Cisco NX-OS Software 6.0(2)A6(1), Cisco NX-OS Software 6.0(2)A6(1a), Cisco NX-OS Software 6.0(2)A6(2), Cisco NX-OS Software 6.0(2)A6(2a), Cisco NX-OS Software 6.0(2)A6(3), Cisco NX-OS Software 6.0(2)A6(3a), Cisco NX-OS Software 6.0(2)A6(4), Cisco NX-OS Software 6.0(2)A6(4a), Cisco NX-OS Software 6.0(2)A6(5), Cisco NX-OS Software 6.0(2)A6(5a), Cisco NX-OS Software 6.0(2)A6(5b), Cisco NX-OS Software 6.0(2)A6(6), Cisco NX-OS Software 6.0(2)A6(7), Cisco NX-OS Software 6.0(2)A6(8), Cisco NX-OS Software 6.0(2)A7(1), Cisco NX-OS Software 6.0(2)A7(1a), Cisco NX-OS Software 6.0(2)A7(2), Cisco NX-OS Software 6.0(2)A7(2a), Cisco NX-OS Software 6.0(2)A8(1), Cisco NX-OS Software 6.0(2)A8(2), Cisco NX-OS Software 6.0(2)A8(3), Cisco NX-OS Software 6.0(2)A8(4), Cisco NX-OS Software 6.0(2)A8(4a), Cisco NX-OS Software 6.0(2)A8(5), Cisco NX-OS Software 6.0(2)A8(6), Cisco NX-OS Software 6.0(2)A8(7), Cisco NX-OS Software 6.0(2)A8(7a), Cisco NX-OS Software 6.0(2)A8(7b), Cisco NX-OS Software 6.0(2)A8(8), Cisco NX-OS Software 6.0(2)A8(9), Cisco NX-OS Software 6.0(2)A8(10a), Cisco NX-OS Software 6.0(2)A8(10), Cisco NX-OS Software 6.2(2), Cisco NX-OS Software 6.2(2a), Cisco NX-OS Software 6.2(6), Cisco NX-OS Software 6.2(6b), Cisco NX-OS Software 6.2(8), Cisco NX-OS Software 6.2(8a), Cisco NX-OS Software 6.2(8b), Cisco NX-OS Software 6.2(10), Cisco NX-OS Software 6.2(12), Cisco NX-OS Software 6.2(18), Cisco NX-OS Software 6.2(16), Cisco NX-OS Software 6.2(14b), Cisco NX-OS Software 6.2(14), Cisco NX-OS Software 6.2(14a), Cisco NX-OS Software 6.2(6a), Cisco NX-OS Software 6.2(20), Cisco NX-OS Software 6.2(1), Cisco NX-OS Software 6.2(3), Cisco NX-OS Software 6.2(5), Cisco NX-OS Software 6.2(5a), Cisco NX-OS Software 6.2(5b), Cisco NX-OS Software 6.2(7), Cisco NX-OS Software 6.2(9), Cisco NX-OS Software 6.2(9a), Cisco NX-OS Software 6.2(9b), Cisco NX-OS Software 6.2(9c), Cisco NX-OS Software 6.2(11), Cisco NX-OS Software 6.2(11b), Cisco NX-OS Software 6.2(11c), Cisco NX-OS Software 6.2(11d), Cisco NX-OS Software 6.2(11e), Cisco NX-OS Software 6.2(13), Cisco NX-OS Software 6.2(13a), Cisco NX-OS Software 6.2(13b), Cisco NX-OS Software 6.2(15), Cisco NX-OS Software 6.2(17), Cisco NX-OS Software 6.2(19), Cisco NX-OS Software 6.2(21), Cisco NX-OS Software 6.2(23), Cisco NX-OS Software 6.2(20a), Cisco NX-OS Software 6.2(25), Cisco NX-OS Software 7.0(3), Cisco NX-OS Software 7.0(0)N1(1), Cisco NX-OS Software 7.0(1)N1(1), Cisco NX-OS Software 7.0(1)N1(3), Cisco NX-OS Software 7.0(2)I2(2c), Cisco NX-OS Software 7.0(2)N1(1), Cisco NX-OS Software 7.0(2)N1(1a), Cisco NX-OS Software 7.0(3)F1(1), Cisco NX-OS Software 7.0(3)F2(1), Cisco NX-OS Software 7.0(3)F2(2), Cisco NX-OS Software 7.0(3)F3(1), Cisco NX-OS Software 7.0(3)F3(2), Cisco NX-OS Software 7.0(3)F3(3), Cisco NX-OS Software 7.0(3)F3(3a), Cisco NX-OS Software 7.0(3)F3(4), Cisco NX-OS Software 7.0(3)F3(3c), Cisco NX-OS Software 7.0(3)F3(3b), Cisco NX-OS Software 7.0(3)F3(5), Cisco NX-OS Software 7.0(3)I1(1), Cisco NX-OS Software 7.0(3)I1(1a), Cisco NX-OS Software 7.0(3)I1(1b), Cisco NX-OS Software 7.0(3)I1(2), Cisco NX-OS Software 7.0(3)I1(3), Cisco NX-OS Software 7.0(3)I1(3a), Cisco NX-OS Software 7.0(3)I1(3b), Cisco NX-OS Software 7.0(3)I2(2a), Cisco NX-OS Software 7.0(3)I2(2b), Cisco NX-OS Software 7.0(3)I2(2c), Cisco NX-OS Software 7.0(3)I2(2d), Cisco NX-OS Software 7.0(3)I2(2e), Cisco NX-OS Software 7.0(3)I2(3), Cisco NX-OS Software 7.0(3)I2(4), Cisco NX-OS Software 7.0(3)I2(5), Cisco NX-OS Software 7.0(3)I2(1), Cisco NX-OS Software 7.0(3)I2(1a), Cisco NX-OS Software 7.0(3)I2(2), Cisco NX-OS Software 7.0(3)I3(1), Cisco NX-OS Software 7.0(3)I4(1), Cisco NX-OS Software 7.0(3)I4(2), Cisco NX-OS Software 7.0(3)I4(3), Cisco NX-OS Software 7.0(3)I4(4), Cisco NX-OS Software 7.0(3)I4(5), Cisco NX-OS Software 7.0(3)I4(6), Cisco NX-OS Software 7.0(3)I4(7), Cisco NX-OS Software 7.0(3)I4(8), Cisco NX-OS Software 7.0(3)I4(8a), Cisco NX-OS Software 7.0(3)I4(8b), Cisco NX-OS Software 7.0(3)I4(8z), Cisco NX-OS Software 7.0(3)I7(5a), Cisco NX-OS Software 7.0(3)I5(1), Cisco NX-OS Software 7.0(3)I5(2), Cisco NX-OS Software 7.0(3)I6(1), Cisco NX-OS Software 7.0(3)I6(2), Cisco NX-OS Software 7.0(3)I7(2), Cisco NX-OS Software 7.3(0.2), Cisco NX-OS Software 7.3(0)D1(1), Cisco NX-OS Software 7.3(0)DX(1), Cisco NX-OS Software 7.3(0)DY(1), Cisco NX-OS Software 7.3(0)N1(1), Cisco NX-OS Software 7.3(0)N1(1b), Cisco NX-OS Software 7.3(0)N1(1a), Cisco NX-OS Software 7.3(1)D1(1B), Cisco NX-OS Software 7.3(1)D1(1), Cisco NX-OS Software 7.3(1)DY(1), Cisco NX-OS Software 7.3(1)N1(0.1), Cisco NX-OS Software 7.3(1)N1(1), Cisco NX-OS Software 7.3(2)D1(1A), Cisco NX-OS Software 7.3(2)D1(1), Cisco NX-OS Software 7.3(2)D1(2), Cisco NX-OS Software 7.3(2)D1(3), Cisco NX-OS Software 7.3(2)D1(3a), Cisco NX-OS Software 7.3(2)N1(0.296), Cisco NX-OS Software 7.3(2)N1(1), Cisco NX-OS Software 7.3(3)N1(1), Cisco NX-OS Software 8.3(1), Cisco NX-OS Software

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2019-1726 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2019-1726 Cisco OpenVuln
Cisco Unified Computing System (Managed) CVE-2019-1726 Cisco OpenVuln
Cisco NX-OS Software CVE-2019-1726 Cisco OpenVuln