cbcvebase.
CVE-2019-1614
published 2019-03-11

CVE-2019-1614: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges…

PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.03%
89.5th percentile
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by the NX-API subsystem. An attacker could exploit this vulnerability by sending malicious HTTP or HTTPS packets to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to perform a command-injection attack and execute arbitrary commands with root privileges. Note: NX-API is disabled by default. MDS 9000 Series Multilayer Switches are affected running software versions prior to 8.1(1b) and 8.2(3). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected running software versions prior to 7.0(3)I7(4). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected running software versions prior to 7.3(4)N1(1). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 7000 and 7700 Series Switches are affected running software versions prior to 7.3(3)D1(1) and 8.2(3).

Affected

20 ranges
VendorProductVersion rangeFixed in
ciscomds_9000_series_multilayer_switches>= unspecified < 8.1(1b)8.1(1b)
ciscomds_9000_series_multilayer_switches>= unspecified < 8.2(3)8.2(3)
cisconexus_3000_series_switches>= unspecified < 7.0(3)I4(9)7.0(3)I4(9)
cisconexus_3000_series_switches>= unspecified < 7.0(3)I7(4)7.0(3)I7(4)
cisconexus_3500_platform_switches>= unspecified < 7.0(3)I7(4)7.0(3)I7(4)
cisconexus_7000_and_7700_series_switches>= unspecified < 7.3(3)D1(1)7.3(3)D1(1)
cisconexus_7000_and_7700_series_switches>= unspecified < 8.2(3)8.2(3)
cisconexus_9000_series_switches_in_standalone_nx-os_mode>= unspecified < 7.0(3)I4(9)7.0(3)I4(9)
cisconexus_9000_series_switches_in_standalone_nx-os_mode>= unspecified < 7.0(3)I7(4)7.0(3)I7(4)
cisconx-os< 7.0\(3\)i4\(9\)7.0\(3\)i4\(9\)
cisconx-os< 7.3\(3\)i4\(9\)7.3\(3\)i4\(9\)
cisconx-os
cisconx-os>= 7.0\(3\) < 7.0\(3\)i7\(4\)7.0\(3\)i7\(4\)
cisconx-os>= 7.0\(3\)i5 < 7.0\(3\)i7\(4\)7.0\(3\)i7\(4\)
cisconx-os>= 7.2 < 7.3\(3\)d1\(1\)7.3\(3\)d1\(1\)
cisconx-os>= 7.3 < 8.1\(1b\)8.1\(1b\)
cisconx-os>= 7.3 < 7.3\(4\)n1\(1\)7.3\(4\)n1\(1\)
cisconx-os>= 8.0 < 8.2\(3\)8.2\(3\)
cisconx-os>= 8.2 < 8.3\(2\)8.3\(2\)
cisconx-os>= 8.3 < 8.3\(2\)8.3\(2\)

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector targets the NX-API management interface via malicious HTTP or HTTPS packets; monitor for anomalous or unexpected HTTP/HTTPS requests to the NX-OS management interface when NX-API is enabled
  • The vulnerability is a command-injection (CWE-78) in the NX-API subsystem; look for OS command injection patterns in HTTP/HTTPS payloads destined for the NX-API endpoint on affected Cisco NX-OS devices
  • Cisco Bug IDs CSCvj17615, CSCvk51420, and CSCvk51423 are associated with this vulnerability and can be used to cross-reference vendor patch and detection content
  • NX-API is disabled by default; audit device configurations to confirm NX-API is not unexpectedly enabled, as enablement is a prerequisite for exploitation
  • ·Exploitation requires NX-API to be enabled on the affected device; the feature is disabled by default, so only devices where it has been explicitly enabled are at risk
  • ·The attacker must be authenticated to exploit this vulnerability; unauthenticated remote exploitation is not possible
  • ·Multiple Cisco NX-OS product lines are affected with different fixed versions: MDS 9000 (fix: 8.1(1b)/8.2(3)), Nexus 3000 (fix: 7.0(3)I4(9)/7.0(3)I7(4)), Nexus 3500 (fix: 7.0(3)I7(4)), Nexus 2000/5500/5600/6000 (fix: 7.3(4)N1(1)), Nexus 9000 Standalone (fix: 7.0(3)I4(9)/7.0(3)I7(4)), Nexus 7000/7700 (fix: 7.3(3)D1(1)/8.2(3))

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.