Cisco NX-OS Software是美国思科(Cisco)公司的一套交换机使用的数据中心级操作系统软件。 Cisco NX-OS Software中的文件系统权限存在访问控制错误漏洞,该漏洞源于程序没有执行较严格的文件系统权限。本地攻击者可通过访问并修改受限制的文件利用该漏洞使用配置文件内容,绕过身份验证并以任意用户身份进行登录。以下产品和版本受到影响:Cisco MDS 9000 Series Multilayer Switches 6.2(25)之前版本,8.1(1b)之前版本,8.3(1)之前
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | MDS 9000 Series Multilayer Switches | unspecified ~ 6.2(25) | - |
|
| Cisco | Nexus 3000 Series Switches | unspecified ~ 7.0(3)I4(9) | - |
|
| Cisco | Nexus 3500 Platform Switches | unspecified ~ 6.0(2)A8(10) | - |
|
| Cisco | Nexus 3600 Platform Switches | unspecified ~ 7.0(3)F3(5) | - |
|
| Cisco | Nexus 2000, 5500, 5600, and 6000 Series Switches | unspecified ~ 7.1(5)N1(1b) | - |
|
| Cisco | Nexus 7000 and 7700 Series Switches | unspecified ~ 6.2(22) | - |
|
| Cisco | Nexus 9000 Series Switches-Standalone | unspecified ~ 7.0(3)I4(9) | - |
|
| Cisco | Nexus 9500 R-Series Line Cards and Fabric Modules | unspecified ~ 7.0(3)F3(5) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-1605 | Cisco NX-OS Software NX-API Arbitrary Code Execution Vulnerability | |
| CVE-2019-1606 | Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606) | |
| CVE-2019-1607 | Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1607) | |
| CVE-2019-1608 | Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1608) | |
| CVE-2019-1609 | Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609) | |
| CVE-2019-1602 | Cisco NX-OS Software Privilege Escalation Vulnerability | |
| CVE-2019-1603 | Cisco NX-OS Software Privilege Escalation Vulnerability | |
| CVE-2019-1604 | Cisco NX-OS Software Privilege Escalation Vulnerability |
No comments yet