CVE-2019-1603
published 2019-03-08CVE-2019-1603: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.1th percentile
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. A successful exploit could allow an attacker to make configuration changes to the system as administrator. Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_9000_series_switches-standalone | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_9500_r-series_line_cards_and_fabric_modules | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nx-os | < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | < 7.0\(3\)f3\(5\) | 7.0\(3\)f3\(5\) |
| cisco | nx-os | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software Privilege Escalation Vulnerability
vendor_cisco·2019-03-06·CVSS 7.8
CVE-2019-1603 [HIGH] CWE-863 Cisco NX-OS Software Privilege Escalation Vulnerability
Cisco NX-OS Software Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level.
The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. A successful exploit could allow an attacker to make configuration changes to the system as administrator.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisc
Cisco
Cisco NX-OS Software Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1603 Cisco NX-OS Software Privilege Escalation Vulnerability
CVE-2019-1603: Cisco NX-OS Software Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. A successful exploit could allow an attacker to make configuration changes to the system as administrator . Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-863, CWE-863
Bug IDs: CSCvh24810, CSCvj00330, CSCvh24810, CSCvh24810, CSCvj00330
GHSA
GHSA-rf22-g3mc-fghj: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrato
ghsa_unreviewed·2022-05-13
CVE-2019-1603 [HIGH] CWE-863 GHSA-rf22-g3mc-fghj: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrato
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. A successful exploit could allow an attacker to make configuration changes to the system as administrator. Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I7(4). Nexus
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-16569 jenkins-mantis-plugin: attackers can connect to an attacker-specified web server leads to XSS
bugzilla·2020-04-01·CVSS 4.3
CVE-2019-16569 [MEDIUM] CVE-2019-16569 jenkins-mantis-plugin: attackers can connect to an attacker-specified web server leads to XSS
CVE-2019-16569 jenkins-mantis-plugin: attackers can connect to an attacker-specified web server leads to XSS
A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
Reference:
http://www.openwall.com/lists/oss-security/2019/12/17/1
Discussion:
External References:
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1603
Bugzilla
CVE-2019-13303 ImageMagick: heap-based buffer over-read in MagickCore/composite.c in CompositeImage
bugzilla·2019-07-16·CVSS 8.8
CVE-2019-13303 [HIGH] CVE-2019-13303 ImageMagick: heap-based buffer over-read in MagickCore/composite.c in CompositeImage
CVE-2019-13303 ImageMagick: heap-based buffer over-read in MagickCore/composite.c in CompositeImage
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1603
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730369]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/d29148fae06c01ef215940e084cf41853c117bab
---
Statement:
This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cv
2019-03-08
Published