cbcvebase.
CVE-2018-0293
published 2018-06-20

CVE-2018-0293: A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.83%
91.0th percentile
A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess valid user credentials for the device. The vulnerability is due to incorrect RBAC privilege assignment for certain CLI commands. An attacker could exploit this vulnerability by authenticating to a device as a nonadministrative user and executing specific commands from the CLI. An exploit could allow the attacker to run commands that should be restricted to administrative users. These commands could modify the configuration or boot image on the device. This vulnerability affects MDS 9000 Series Multilayer Switches, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvd77904.

Affected

7 ranges
VendorProductVersion rangeFixed in
cisconx-os
cisconx-os
cisconx-os
cisconx-os>= 5.2 < 8.1\(1\)8.1\(1\)
cisconx-os>= 6.0 < 7.3\(3\)n1\(1\)7.3\(3\)n1\(1\)
cisconx-os>= 6.0 < 7.0\(3\)i7\(2\)7.0\(3\)i7\(2\)
cisconx-os>= 7.0\(3\)i4 < 7.0\(3\)i7\(1\)7.0\(3\)i7\(1\)

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for non-administrative users executing CLI commands that modify device configuration or boot image on Cisco NX-OS devices, which should normally be restricted to administrative roles.
  • Alert on authenticated remote sessions from non-administrative accounts issuing privileged CLI commands on affected Cisco NX-OS platforms (MDS 9000, Nexus 2000/3000/3500/3600/5500/5600/6000/7000/7700/9000 series).
  • ·The vulnerability stems from incorrect RBAC privilege assignment in NX-OS; there are no workarounds available — patching is the only remediation.
  • ·Exploitation requires valid (non-administrative) user credentials on the device; unauthenticated exploitation is not possible.
  • ·Cisco Bug ID CSCvd77904 tracks this issue across all affected NX-OS platforms.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.