CVE-2017-12341Command Injection in Cisco Nx-os

CWE-77Command Injection4 documents4 sources
Severity
6.7MEDIUMNVD
EPSS
0.4%
top 37.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installation of a software patch. An attacker could exploit this vulnerability by installing a crafted patch image with the vulnerable operation occurring prior to patch activation. An exploit could allow the

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDcisco/unified_computing_system7.0\(0\)hsk\(0.357\)
NVDcisco/nx-os8.1\(0.59\)s0, 8.1\(1\)+1

🔴Vulnerability Details

2
GHSA
GHSA-q7rq-5p3w-xqv4: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack2022-05-13
CVEList
CVE-2017-12341: A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack2017-11-30

📋Vendor Advisories

1
Cisco
Cisco NX-OS System Software Patch Installation Command Injection Vulnerability2017-11-29
CVE-2017-12341 — Command Injection in Cisco Nx-os | cvebase