CVE-2019-1600
published 2019-03-07CVE-2019-1600: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive…
PriorityP419medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.38%
30.6th percentile
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow the attacker to access sensitive and critical files. Firepower 4100 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. Firepower 9300 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. MDS 9000 Series Multilayer Switches are affected in versions prior to 6.2(25), 8.1(1b), and 8.3(1). Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected in versions prior to 7.1(5)N1(1b) and 7.3(3)N1(1). Nexus 7000 and 7700 Series Switches are affected in versions prior to 6.2(22), 7.3(3)D1(1), and 8.2(3). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < 2.2.2.91 | 2.2.2.91 |
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < 2.3.1.110 | 2.3.1.110 |
| cisco | firepower_9300_series_next-generation_firewalls | >= unspecified < 2.2.2.91 | 2.2.2.91 |
| cisco | firepower_9300_series_next-generation_firewalls | >= unspecified < 2.3.1.110 | 2.3.1.110 |
| cisco | firepower_extensible_operating_system | >= 1.1 < 2.2.2.91 | 2.2.2.91 |
| cisco | firepower_extensible_operating_system | >= 2.3 < 2.3.1.110 | 2.3.1.110 |
| cisco | fxos_and_nx-os | — | — |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 6.2(25) | 6.2(25) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.1(1b) | 8.1(1b) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.3(1) | 8.3(1) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 6.0(2)A8(10) | 6.0(2)A8(10) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 6.2(22) | 6.2(22) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 7.3(3)D1(1) | 7.3(3)D1(1) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_9000_series_switches-standalone | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_9000_series_switches-standalone | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_9500_r-series_line_cards_and_fabric_modules | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nx-os | < 7.0\(3\)i4\(9\) | 7.0\(3\)i4\(9\) |
| cisco | nx-os | < 6.0\(2\)a8\(10\) | 6.0\(2\)a8\(10\) |
| cisco | nx-os | < 7.1\(5\)n1\(1b\) | 7.1\(5\)n1\(1b\) |
| cisco | nx-os | < 6.2\(22\) | 6.2\(22\) |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
vendor_redhat·2025-09-17·CVSS 5.5
CVE-2023-53344 [MEDIUM] CWE-390 kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in vfs_write
Syzkaller reported the following issue:
BUG: KMSAN: uninit-value in aio_rw_done fs/aio.c:1520 [inline]
BUG: KMSAN: uninit-value in aio_write+0x899/0x950 fs/aio.c:1600
aio_rw_done fs/aio.c:1520 [inline]
aio_write+0x899/0x950 fs/aio.c:1600
io_submit_one+0x1d1c/0x3bf0 fs/aio.c:2019
__do_sys_io_submit fs/aio.c:2078 [inline]
__se_sys_io_submit+0x293/0x770 fs/aio.c:2048
__x64_sys_io_submit+0x92/0xd0 fs/aio.c:2048
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
Uninit was created at:
slab_pos
Cisco
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
vendor_cisco·2019-03-06·CVSS 6.7
CVE-2019-1600 [MEDIUM] CWE-732 Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system.
The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow the attacker to access sensitive and critical files.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSe
Cisco
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1600 Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
CVE-2019-1600: Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow the attacker to access sensitive and critical files. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-732, CWE-732
Bug IDs: CSCvh75886, CSCvh75949, CSCvi96549, CSCvh75886, CSCvh75949
GHSA
GHSA-jxp7-39vp-v468: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access
ghsa_unreviewed·2022-05-11
CVE-2019-1600 [MEDIUM] CWE-732 GHSA-jxp7-39vp-v468: A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow the attacker to access sensitive and critical files. Firepower 4100 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. Firepower 9300 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. MDS 9000 Series Multilayer Switches are affected in versions prior to 6.2(25), 8.1(1b), and 8.3(1). Nex
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53344 kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
bugzilla·2025-09-17·CVSS 5.5
CVE-2023-53344 [MEDIUM] CVE-2023-53344 kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
CVE-2023-53344 kernel: Linux Kernel: Denial of Service in CAN BCM due to uninitialized memory read
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: bcm_tx_setup(): fix KMSAN uninit-value in vfs_write
Syzkaller reported the following issue:
BUG: KMSAN: uninit-value in aio_rw_done fs/aio.c:1520 [inline]
BUG: KMSAN: uninit-value in aio_write+0x899/0x950 fs/aio.c:1600
aio_rw_done fs/aio.c:1520 [inline]
aio_write+0x899/0x950 fs/aio.c:1600
io_submit_one+0x1d1c/0x3bf0 fs/aio.c:2019
__do_sys_io_submit fs/aio.c:2078 [inline]
__se_sys_io_submit+0x293/0x770 fs/aio.c:2048
__x64_sys_io_submit+0x92/0xd0 fs/aio.c:2048
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x63/0xcd
Uninit was c
Bugzilla
CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
bugzilla·2019-07-02·CVSS 5.5
CVE-2019-13134 [MEDIUM] CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
CVE-2019-13134 ImageMagick: a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1600
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726082]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/fe3066122ef72c82415811d25e9e3fad622c0a99
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/210474b2fac6a661bfa7ed563213920e93e76395
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now cl
Bugzilla
CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
bugzilla·2019-07-02·CVSS 5.5
CVE-2019-13133 [MEDIUM] CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
CVE-2019-13133 ImageMagick: a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1600
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726079]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/fe3066122ef72c82415811d25e9e3fad622c0a99
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/210474b2fac6a661bfa7ed563213920e93e76395
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed
http://www.securityfocus.com/bid/107399http://www.securityfocus.com/bid/107404https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-directoryhttp://www.securityfocus.com/bid/107399http://www.securityfocus.com/bid/107404https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-directory
2019-03-07
Published