CVE-2019-1602
published 2019-03-08CVE-2019-1602: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.5th percentile
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator. The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of an affected device, accessing a specific file, and leveraging this information to authenticate to the NX-API server. A successful exploit could allow an attacker to make configuration changes as administrator. Note: NX-API is disabled by default. Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_9000_series_switches-standalone | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_9500_r-series_line_cards_and_fabric_modules | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nx-os | — | — |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)f3\(5\) | 7.0\(3\)f3\(5\) |
| cisco | nx-os | >= 7.0\(3\)f1 < 7.0\(3\)f3\(5\) | 7.0\(3\)f3\(5\) |
| cisco | nx-os | >= 7.0\(3\)f3 < 7.0\(3\)f3\(5\) | 7.0\(3\)f3\(5\) |
| cisco | nx-os | >= 7.0\(3\)i5 < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software Privilege Escalation Vulnerability
vendor_cisco·2019-03-06·CVSS 7.8
CVE-2019-1602 [HIGH] CWE-264 Cisco NX-OS Software Privilege Escalation Vulnerability
Cisco NX-OS Software Privilege Escalation Vulnerability
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator.
The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of an affected device, accessing a specific file, and leveraging this information to authenticate to the NX-API server. A successful exploit could allow an attacker to make configuration changes as administrator.
Note: NX-API is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This adv
Cisco
Cisco NX-OS Software Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1602 Cisco NX-OS Software Privilege Escalation Vulnerability
CVE-2019-1602: Cisco NX-OS Software Privilege Escalation Vulnerability
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator . The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of an affected device, accessing a specific file, and leveraging this information to authenticate to the NX-API server. A successful exploit could allow an attacker to make configuration changes as administrator . Note : NX-API is disabled by default. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-264, CWE-264
Bug IDs:
GHSA
GHSA-4wp2-63h4-86r7: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could
ghsa_unreviewed·2022-05-13
CVE-2019-1602 [HIGH] GHSA-4wp2-63h4-86r7: A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive data that could be used to elevate their privileges to administrator. The vulnerability is due to improper implementation of filesystem permissions. An attacker could exploit this vulnerability by logging in to the CLI of an affected device, accessing a specific file, and leveraging this information to authenticate to the NX-API server. A successful exploit could allow an attacker to make configuration changes as administrator. Note: NX-API is disabled by default. Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in v
No detection rules found.
2019-03-08
Published