CVE-2019-1614
published 2019-03-11CVE-2019-1614: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.07%
89.6th percentile
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to perform a command-injection attack and execute arbitrary commands with root privileges. Note: NX-API is disabled by default. MDS 9000 Series Multilayer Switches are affected running software versions prior to 8.1(1b) and 8.2(3). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 7.0(3)I7(4). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected running software versions prior to 7.3(4)N1(1). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 7000 and 7700 Series Switches are affected running software versions prior to 7.3(3)D1(1) and 8.2(3).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.1(1b) | 8.1(1b) |
| cisco | mds_9000_series_multilayer_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_3000_series_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_3500_platform_switches | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 7.3(3)D1(1) | 7.3(3)D1(1) |
| cisco | nexus_7000_and_7700_series_switches | >= unspecified < 8.2(3) | 8.2(3) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I4(9) | 7.0(3)I4(9) |
| cisco | nexus_9000_series_switches_in_standalone_nx-os_mode | >= unspecified < 7.0(3)I7(4) | 7.0(3)I7(4) |
| cisco | nx-os | < 7.0\(3\)i4\(9\) | 7.0\(3\)i4\(9\) |
| cisco | nx-os | < 7.3\(3\)i4\(9\) | 7.3\(3\)i4\(9\) |
| cisco | nx-os | — | — |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | >= 7.0\(3\)i5 < 7.0\(3\)i7\(4\) | 7.0\(3\)i7\(4\) |
| cisco | nx-os | >= 7.2 < 7.3\(3\)d1\(1\) | 7.3\(3\)d1\(1\) |
| cisco | nx-os | >= 7.3 < 8.1\(1b\) | 8.1\(1b\) |
| cisco | nx-os | >= 7.3 < 7.3\(4\)n1\(1\) | 7.3\(4\)n1\(1\) |
| cisco | nx-os | >= 8.0 < 8.2\(3\) | 8.2\(3\) |
| cisco | nx-os | >= 8.2 < 8.3\(2\) | 8.3\(2\) |
| cisco | nx-os | >= 8.3 < 8.3\(2\) | 8.3\(2\) |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector targets the NX-API management interface via malicious HTTP or HTTPS packets; monitor for anomalous or unexpected HTTP/HTTPS requests to the NX-OS management interface when NX-API is enabled ↗
- →The vulnerability is a command-injection (CWE-78) in the NX-API subsystem; look for OS command injection patterns in HTTP/HTTPS payloads destined for the NX-API endpoint on affected Cisco NX-OS devices ↗
- →Cisco Bug IDs CSCvj17615, CSCvk51420, and CSCvk51423 are associated with this vulnerability and can be used to cross-reference vendor patch and detection content ↗
- →NX-API is disabled by default; audit device configurations to confirm NX-API is not unexpectedly enabled, as enablement is a prerequisite for exploitation ↗
- ·Exploitation requires NX-API to be enabled on the affected device; the feature is disabled by default, so only devices where it has been explicitly enabled are at risk ↗
- ·The attacker must be authenticated to exploit this vulnerability; unauthenticated remote exploitation is not possible ↗
- ·Multiple Cisco NX-OS product lines are affected with different fixed versions: MDS 9000 (fix: 8.1(1b)/8.2(3)), Nexus 3000 (fix: 7.0(3)I4(9)/7.0(3)I7(4)), Nexus 3500 (fix: 7.0(3)I7(4)), Nexus 2000/5500/5600/6000 (fix: 7.3(4)N1(1)), Nexus 9000 Standalone (fix: 7.0(3)I4(9)/7.0(3)I7(4)), Nexus 7000/7700 (fix: 7.3(3)D1(1)/8.2(3)) ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software NX-API Command Injection Vulnerability
vendor_cisco·2019-03-06·CVSS 8.8
CVE-2019-1614 [HIGH] CWE-78 Cisco NX-OS Software NX-API Command Injection Vulnerability
Cisco NX-OS Software NX-API Command Injection Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to perform a command-injection attack and execute arbitrary commands with root privileges.
Note: NX-API is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco
Cisco NX-OS Software NX-API Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1614 Cisco NX-OS Software NX-API Command Injection Vulnerability
CVE-2019-1614: Cisco NX-OS Software NX-API Command Injection Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to perform a command-injection attack and execute arbitrary commands with root privileges. Note : NX-API is disabled by default. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-78, CWE-78
B
GHSA
GHSA-hq92-fm59-p6hc: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root pr
ghsa_unreviewed·2022-05-13
CVE-2019-1614 [HIGH] CWE-78 GHSA-hq92-fm59-p6hc: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root pr
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to perform a command-injection attack and execute arbitrary commands with root privileges. Note: NX-API is disabled by default. MDS 9000 Series Multilayer Switches are affected running software versions prior to 8.1(1b) and 8.2(3). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9
No detection rules found.
No public exploits indexed.
Tenable
Cisco March Advisory Addresses Multiple Vulnerabilities in FXOS and NX-OS
blogs_tenable·2019-03-07
Cisco March Advisory Addresses Multiple Vulnerabilities in FXOS and NX-OS
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
bugzilla·2019-07-16·CVSS 7.8
CVE-2019-13304 [HIGH] CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
CVE-2019-13304 ImageMagick: stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1614
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1730365]
---
Upstream patches:
https://github.com/ImageMagick/ImageMagick6/commit/bfa3b9610c83227894c92b0d312ad327fceb6241
https://github.com/ImageMagick/ImageMagick/commit/7689875ef64f34141e7292f6945efdf0530b4a5e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This
2019-03-11
Published