← Back

CVE-2018-0337

nvd nist
Published: Jun 21, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected device. A successful exploit could allow the attacker to cause other users to execute unwanted, arbitrary commands on the affected device. Cisco Bug IDs: CSCvd06339, CSCvd15698, CSCvd36108, CSCvf52921, CSCvf52930, CSCvf52953, CSCvf52976.

Affected (12)

Products: Cisco: Nx Os
1 product
Nx Os
Configuration A
4 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 7.0(8)n1(1)
Version 7.1(4)n1(1)
Version 7.3(1)n1(0.6)
Version 7.3(2)n1(0.350)
Running on/withPlatform Versions
Cisco
Nexus 5000
All versions
Cisco
Nexus 5010
All versions
Cisco
Nexus 5020
All versions
Cisco
Nexus 5548p
All versions
Cisco
Nexus 5548up
All versions
Cisco
Nexus 5596t
All versions
Cisco
Nexus 5596up
All versions
Cisco
Nexus 56128p
All versions
Cisco
Nexus 5624q
All versions
Cisco
Nexus 5648q
All versions
Cisco
Nexus 5672up
All versions
Cisco
Nexus 5696q
All versions
Configuration B
8 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 7.3(1)dx(0.119)
Version 7.3(3)d1(0.2)
Version 8.0(0.54)s0
Version 8.1(0.9)
Version 8.1(0)bd(0.20)
Version 8.2(0.4)s0
Version 8.3(0)spg(0.30)
Version 8.8(3.5)s0
Running on/withPlatform Versions
Cisco
Nexus 7000
All versions
Cisco
Nexus 7700
All versions

Timeline

No history available yet.