CVE-2019-1593
published 2019-03-06CVE-2019-1593: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
29.8th percentile
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerability.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_9000_series_fabric_switches_in_aci_mode | >= unspecified < 13.2(4d) | 13.2(4d) |
| cisco | nexus_9000_series_fabric_switches_in_aci_mode | >= unspecified < 14.0(1h) | 14.0(1h) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nx-os | < 13.2\(4d\) | 13.2\(4d\) |
| cisco | nx-os | — | — |
| cisco | nx-os | >= 14.0 < 14.0\(1h\) | 14.0\(1h\) |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)f3\(5\) | 7.0\(3\)f3\(5\) |
| cisco | nx-os | >= 7.0\(3\)i4 < 7.0\(3\)i4\(9\) | 7.0\(3\)i4\(9\) |
| cisco | nx-os | >= 7.0\(3\)i5 < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | >= 8.1 < 8.2\(3\) | 8.2\(3\) |
| cisco | nx-os | >= 8.3 < 8.3\(1\) | 8.3\(1\) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
vendor_cisco·2019-03-06·CVSS 7.8
CVE-2019-1593 [HIGH] CWE-264 Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials.
The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev
Cisco
Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1593 Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
CVE-2019-1593: Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For
GHSA
GHSA-r3m8-6ph3-2x9x: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege lev
ghsa_unreviewed·2022-05-13
CVE-2019-1593 [HIGH] GHSA-r3m8-6ph3-2x9x: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege lev
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerabili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-06
Published