CVE-2017-12335

CWE-77Command Injection4 documents4 sources
Severity
6.3MEDIUM
EPSS
0.4%
top 41.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command and gain unauthorized access to the underlying operating system of the device. An exploit could allow the attacker to execute arbitrary commands at the user's privi

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:LExploitability: 2.0 | Impact: 3.7

Affected Packages3 packages

NVDcisco/unified_computing_system7.0\(0\)hsk\(0.357\)
CVEListV5cisco_nx-osCisco NX-OS
NVDcisco/nx-os7.0\(0\)hsk\(0.357\), 8.1\(0\)bd\(0.20\), 8.1\(1\)+2

🔴Vulnerability Details

2
GHSA
GHSA-46wq-r5q9-qq5f: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack2022-05-13
CVEList
CVE-2017-12335: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack2017-11-30

📋Vendor Advisories

1
Cisco
Cisco NX-OS System Software CLI Command Injection Vulnerability2017-11-30
CVE-2017-12335 (MEDIUM CVSS 6.3) | A vulnerability in the CLI of Cisco | cvebase.io