CVE-2013-1191
published 2014-05-26CVE-2013-1191: Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain…
PriorityP334high7.1CVSS 2.0
AVNACHAuSCCICAC
EPSS
1.87%
77.2th percentile
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os-based_products | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9cw5-jjwx-8c3g: Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2013-1191 [HIGH] GHSA-9cw5-jjwx-8c3g: Cisco NX-OS 6
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
Cisco
Multiple Vulnerabilities in Cisco NX-OS-Based Products
vendor_cisco·2014-05-21·CVSS 7.8
CVE-2013-1191 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco NX-OS-Based Products
Multiple Vulnerabilities in Cisco NX-OS-Based Products
Cisco Nexus, Cisco Unified Computing System (UCS), and Cisco 1000 Series Connected Grid Routers (CGR) are all based on the Cisco NX-OS operating system. These products are affected by one or more of the following vulnerabilities:
Cisco NX-OS Virtual Device Context SSH Privilege Escalation Vulnerability
Cisco NX-OS Virtual Device Context SSH Key Privilege Escalation Vulnerability
Cisco NX-OS-Based Products Smart Call Home Buffer Overflow Vulnerability
Cisco NX-OS Message Transfer Service Denial of Service Vulnerability
No officially released images are affected
Cisco has released software updates that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center
Cisco
Multiple Vulnerabilities in Cisco NX-OS-Based Products
vendor_cisco
CVE-2013-1191 Multiple Vulnerabilities in Cisco NX-OS-Based Products
CVE-2013-1191: Multiple Vulnerabilities in Cisco NX-OS-Based Products
Cisco Nexus, Cisco Unified Computing System (UCS), and Cisco 1000 Series Connected Grid Routers (CGR) are all based on the Cisco NX-OS operating system. These products are affected by one or more of the following vulnerabilities: Cisco NX-OS Virtual Device Context SSH Privilege Escalation Vulnerability Cisco NX-OS Virtual Device Context SSH Key Privilege Escalation Vulnerability Cisco NX-OS-Based Products Smart Call Home Buffer Overflow Vulnerability Cisco NX-OS Message Transfer Service Denial of Service Vulnerability No officially released images are affected Cisco has released software updates that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-26
Published