Cisco Nexus 9000 Series ACI Mode Switch Software 14.0(3d)之前版本中的CLI命令的实现存在权限许可和访问控制漏洞,该漏洞源于程序没有充分地过滤用户提交的输入。本地攻击者可通过向设备的CLI进行身份验证并发送命令利用该漏洞绕过被限制的shell,以root级别的权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco NX-OS Software for Nexus 9000 Series Fabric Switches ACI Mode | 14.0(3d) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-1588 | Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Arbitrary | |
| CVE-2019-1593 | Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vuln | |
| CVE-2019-1594 | Cisco NX-OS Software 802.1X Extensible Authentication Protocol over LAN Denial of Service | |
| CVE-2019-1595 | Cisco Nexus 5600 and 6000 Series Switches Fibre Channel over Ethernet Denial of Service Vu | |
| CVE-2019-1585 | Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Privilege |
No comments yet