CVE-2017-12340Improper Access Control in Cisco Nx-os

Severity
4.2MEDIUMNVD
EPSS
0.1%
top 67.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain functions of the Python scripting sandbox of the affected sy

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 0.8 | Impact: 3.4

Affected Packages1 packages

NVDcisco/nx-os8.1\(0.70\)s0

🔴Vulnerability Details

2
GHSA
GHSA-7fgx-h5gw-66x7: A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 772022-05-13
CVEList
CVE-2017-12340: A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 772017-11-30

📋Vendor Advisories

1
Cisco
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability2017-11-29
CVE-2017-12340 — Improper Access Control in Cisco Nx-os | cvebase