← Back

CVE-2018-0294

nvd nist
Published: Jun 20, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear the device configuration and reload a device. An attacker could exploit this vulnerability by logging into an affected device as an administrative user and configuring an unauthorized account for the device. The account would not require a password for authentication and would be accessible only via a Secure Shell (SSH) connection to the device. A successful exploit could allow the attacker to configure an unauthorized account that has administrative privileges, does not require a password for authentication, and does not appear in the running configuration or the audit logs for the affected device. This vulnerability affects Firepower 4100 Series Next-Generation Firewalls, Firepower 9300 Security Appliance, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Fabric Extenders, Nexus 3500 Platform Switches, Nexus 4000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvd13993, CSCvd34845, CSCvd34857, CSCvd34862, CSCvd34879, CSCve35753.

Affected (8)

3 products
Nx Os
Fxos
Configuration A
1 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Version 7.3(2)n1(0.354)
Running on/withPlatform Versions
Cisco
Nexus 5000
All versions
Cisco
Nexus 5010
All versions
Cisco
Nexus 5020
All versions
Cisco
Nexus 5548p
All versions
Cisco
Nexus 5548up
All versions
Cisco
Nexus 5596t
All versions
Cisco
Nexus 5596up
All versions
Cisco
Nexus 56128p
All versions
Cisco
Nexus 5624q
All versions
Cisco
Nexus 5648q
All versions
Cisco
Nexus 5672up
All versions
Cisco
Nexus 5696q
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 5.2(1)sv3(1.10)
Running on/withPlatform Versions
Cisco
Nexus 1000v
All versions
Configuration C
1 vulnerable · 19 platform
Vulnerable SoftwareAffected Versions
Version 8.8(3.5)s0
Running on/withPlatform Versions
Cisco
Nexus 92160yc X
All versions
Cisco
Nexus 92304qc
All versions
Cisco
Nexus 9236c
All versions
Cisco
Nexus 9272q
All versions
Cisco
Nexus 93108tc Ex
All versions
Cisco
Nexus 93120tx
All versions
Cisco
Nexus 93128tx
All versions
Cisco
Nexus 93180yc Ex
All versions
Cisco
Nexus 9332pq
All versions
Cisco
Nexus 9372px
All versions
Cisco
Nexus 9372tx
All versions
Cisco
Nexus 9396px
All versions
Cisco
Nexus 9396tx
All versions
Cisco
Nexus 9504
All versions
Cisco
Nexus 9508
All versions
Cisco
Nexus 9516
All versions
Cisco
Nexus N9k C9508 Fm R
All versions
Cisco
Nexus N9k X9636c R
All versions
Cisco
Nexus N9k X9636q R
All versions
Configuration D
28 platform
Running on/withPlatform Versions
Cisco
Nexus 172tq Xl
All versions
Cisco
Nexus 3016
All versions
Cisco
Nexus 3048
All versions
Cisco
Nexus 3064 32t
All versions
Cisco
Nexus 3064 T
All versions
Cisco
Nexus 3064 X
All versions
Cisco
Nexus 3100 V
All versions
Cisco
Nexus 31128pq
All versions
Cisco
Nexus 3132c Z
All versions
Cisco
Nexus 3132q
All versions
Cisco
Nexus 3132q X
All versions
Cisco
Nexus 3132q Xl
All versions
Cisco
Nexus 3164q
All versions
Cisco
Nexus 3172pq
All versions
Cisco
Nexus 3172pq Xl
All versions
Cisco
Nexus 3172tq
All versions
Cisco
Nexus 3172tq 32t
All versions
Cisco
Nexus 3232c
All versions
Cisco
Nexus 3264c E
All versions
Cisco
Nexus 3264q
All versions
Cisco
Nexus 34180yc
All versions
Cisco
Nexus 3524 X
All versions
Cisco
Nexus 3524 Xl
All versions
Cisco
Nexus 3548
All versions
Cisco
Nexus 3548 X
All versions
Cisco
Nexus 3548 Xl
All versions
Cisco
Nexus 3636c R
All versions
Cisco
Nexus C36180yc R
All versions
Configuration E
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Version 7.0(3)i2(4a)
Running on/withPlatform Versions
Cisco
Ucs 6120xp
All versions
Cisco
Ucs 6140xp
All versions
Cisco
Ucs 6248up
All versions
Cisco
Ucs 6296up
All versions
Cisco
Ucs 6324
All versions
Cisco
Ucs 6332
All versions
Configuration F
4 platform
Running on/withPlatform Versions
Cisco
Firepower 4110
All versions
Cisco
Firepower 4120
All versions
Cisco
Firepower 4140
All versions
Cisco
Firepower 4150
All versions
Configuration G
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
From 2.1.1 to 2.1.1.86
From 2.2 to 2.2.2.17
From 1.1 to 2.0.1.159
Running on/withPlatform Versions
Cisco
Firepower 9300 Security Appliance
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.1(2)e1(1a)
Running on/withPlatform Versions
Cisco
Nexus 4001
All versions

Related CWEs

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.