CVE-2017-12338 — Improper Input Validation in Cisco LAN Switch Software
Severity
6.0MEDIUMNVD
EPSS
0.2%
top 63.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 13
Description
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted command on the CLI. An exploit could allow the attacker unauthorized access to read arbitrary files on the underlying local file system. On products that support multiple virtual device contexts (VDCs), t…
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 1.5 | Impact: 4.0
Affected Packages3 packages
🔴Vulnerability Details
2GHSA▶
GHSA-p6qh-hf5h-ppmg: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files↗2022-05-13
CVEList▶
CVE-2017-12338: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files↗2017-11-30