CVE-2019-1611
published 2019-03-11CVE-2019-1611: A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the…
PriorityP336medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.46%
37.3th percentile
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability. Firepower 4100 Series Next-Generation Firewalls are affected running software versions prior to 2.2.2.91, 2.3.1.110, and 2.4.1.222. Firepower 9300 Security Appliance are affected running software versions prior to 2.2.2.91, 2.3.1.110, and 2.4.1.222. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25) and 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(5). Nexus 3500 Platform Switches are affected running software versions prior to 7.0(3)I7(5). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected running software versions prior to 7.1(5)N1(1b) and 7.3(4)N1(1). Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22), 7.3(3)D1(1), 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(5). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < 2.2.2.91 | 2.2.2.91 |
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < 2.3.1.110 | 2.3.1.110 |
| cisco | firepower_4100_series_next-generation_firewalls | >= unspecified < 2.4.1.222 | 2.4.1.222 |
| cisco | firepower_9300_security_appliance | >= unspecified < 2.2.2.91 | 2.2.2.91 |
| cisco | firepower_9300_security_appliance | >= unspecified < 2.3.1.110 | 2.3.1.110 |
| cisco | firepower_9300_security_appliance | >= unspecified < 2.4.1.222 | 2.4.1.222 |
| cisco | fx-os | >= 1.1 < 2.2.2.91 | 2.2.2.91 |
| cisco | fx-os | >= 2.3 < 2.3.1.110 | 2.3.1.110 |
| cisco | fx-os | >= 2.4 < 2.4.1.222 | 2.4.1.222 |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 6.2(25) | 6.2(25) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.3(1) | 8.3(1) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(5) | 7.0(3)I7(5) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(5) | 7.0(3)I7(5) |
| cisco | nexus_3600_platform_switches | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 6.2(22) | 6.2(22) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 7.3(3)D1(1) | 7.3(3)D1(1) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I7(5) | 7.0(3)I7(5) |
| cisco | nexus_9500_r-series_line_cards_and_fabric_modules | >= unspecified < 7.0(3)F3(5) | 7.0(3)F3(5) |
| cisco | nx-os | < 7.0\(3\)i4\(9\) | 7.0\(3\)i4\(9\) |
| cisco | nx-os | < 6.2\(22\) | 6.2\(22\) |
| cisco | nx-os | < 7.3\(3\)i7\(5\) | 7.3\(3\)i7\(5\) |
| cisco | nx-os | < 7.1\(5\)n1\(1b\) | 7.1\(5\)n1\(1b\) |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.04.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
vendor_cisco·2019-03-06·CVSS 6.7
CVE-2019-1611 [MEDIUM] CWE-88 Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
Cisco has released software updates that address this vulnerability. There
Cisco
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)
vendor_cisco·CVSS 3.0
CVE-2019-1611 Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)
CVE-2019-1611: Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid user credentials to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-88
GHSA
GHSA-54p7-622p-mpvw: A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands
ghsa_unreviewed·2022-05-13
CVE-2019-1611 [HIGH] CWE-88 GHSA-54p7-622p-mpvw: A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability. Firepower 4100 Series Next-Generation Firewalls are affected running software versions prior to 2.2.2.91, 2.3.1.110, and 2.4.1.222. Firepower 9300 Security Ap
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14558 edk2: potentially leaking of secret information due to uncleared memory
bugzilla·2020-05-08·CVSS 5.7
CVE-2019-14558 [MEDIUM] CVE-2019-14558 edk2: potentially leaking of secret information due to uncleared memory
CVE-2019-14558 edk2: potentially leaking of secret information due to uncleared memory
An issue was discovered in edk2. Freed memory was not cleared in some cases, potentially leaking secret information.
Reference:
https://bugzilla.tianocore.org/show_bug.cgi?id=1611
Upstream commits:
https://github.com/tianocore/edk2/commit/764e8ba1389a617639d79d2c4f0d53f4ea4a7387
https://github.com/tianocore/edk2/commit/f1d78c489a39971b5aac5d2fc8a39bfa925c3c5d
Discussion:
Created edk2 tracking bugs for this issue:
Affects: epel-all [bug 1833349]
Affects: fedora-all [bug 1833348]
---
Marking rhel-7/ovmf and rhel-8/edk2 as notaffected based on https://bugzilla.tianocore.org/show_bug.cgi?id=1611#c9 .
---
This bug is now closed. Further updates for individual products will be reflected on the CVE pa
Bugzilla
CVE-2019-13298 ImageMagick: heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error
bugzilla·2019-07-17·CVSS 8.8
CVE-2019-13298 [HIGH] CVE-2019-13298 ImageMagick: heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error
CVE-2019-13298 ImageMagick: heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1611
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730594]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/d4fc44b58a14f76b1ac997517d742ee12c9dc5d3
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13298
2019-03-11
Published