CVE-2011-2569
published 2011-10-27CVE-2011-2569: Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows…
PriorityP423medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.33%
25.1th percentile
Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | unified_computing_system_infrastructure_and_unified_computing_system_software | — | — |
| cisco | unified_computing_system_infrastructure_and_unified_computing_system_software | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus OS Software Command Injection Vulnerability
vendor_cisco·2011-10-27·CVSS 6.8
CVE-2011-2569 [MEDIUM] CWE-264 Cisco Nexus OS Software Command Injection Vulnerability
Cisco Nexus OS Software Command Injection Vulnerability
Cisco Nexus OS contains a vulnerability that could allow an authenticated, local attacker to execute arbitrary commands on a targeted device.
The vulnerability is due to improper sanitization of user-supplied values to command line interface commands. An authenticated, local attacker could exploit the vulnerability by issuing commands that contain malicious options on the device command line interface. If successful, the attacker could gain elevated privileges on the targeted device.
Cisco confirmed the vulnerability within software release notes and released software updates.
To exploit this vulnerability, an attacker must log in locally to a vulnerable device. Because of the critical function that affected products often serve in
GHSA
GHSA-4f6p-cv97-w83q: Cisco Nexus OS (aka NX-OS) 4
ghsa_unreviewed·2022-05-14
CVE-2011-2569 [MEDIUM] GHSA-4f6p-cv97-w83q: Cisco Nexus OS (aka NX-OS) 4
Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-10-27
Published