CVE-2019-1596Incorrect Permission Assignment in Cisco Nexus 3000 Series Switches

Severity
7.8HIGHNVD
EPSS
0.2%
top 64.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 13

Description

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with valid user credentials. The vulnerability is due to incorrect permissions of a system executable. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege le

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5cisco/nexus_9000_series_switches_in_standalone_nx-os_modeunspecified7.0(3)I7(4)
CVEListV5cisco/nexus_3000_series_switchesunspecified7.0(3)I7(4)
CVEListV5cisco/nexus_9500_r-series_line_cards_and_fabric_modulesunspecified7.0(3)F3(5)
CVEListV5cisco/nexus_3500_platform_switchesunspecified7.0(3)I7(4)
CVEListV5cisco/nexus_3600_platform_switchesunspecified7.0(3)F3(5)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gqv4-4m7f-x3p4: A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege lev2022-05-13
CVEList
Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability2019-03-07

📋Vendor Advisories

1
Cisco
Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability2019-03-06
CVE-2019-1596 — Incorrect Permission Assignment | cvebase