CVE-2017-12338Improper Input Validation in Cisco LAN Switch Software

Severity
6.0MEDIUMNVD
EPSS
0.2%
top 63.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An exploit could allow the attacker unauthorized access to read arbitrary files on the underlying local file system. On products that support multiple virtual device contexts (VDCs), t

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 1.5 | Impact: 4.0

Affected Packages3 packages

NVDcisco/unified_computing_system7.0\(0\)hsk\(0.357\)
NVDcisco/lan_switch_software12.2\(1.107\)
NVDcisco/nx-os8.0\(1\), 8.1\(0\)bd\(0.20\), 8.1\(1\)+2

🔴Vulnerability Details

2
GHSA
GHSA-p6qh-hf5h-ppmg: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files2022-05-13
CVEList
CVE-2017-12338: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files2017-11-30

📋Vendor Advisories

1
Cisco
Cisco NX-OS System Software CLI Arbitrary File Read Vulnerability2017-11-30
CVE-2017-12338 — Improper Input Validation in Cisco | cvebase