CVE-2019-1726
published 2019-05-15CVE-2019-1726: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.4th percentile
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | >= unspecified < 6.2(25) | 6.2(25) |
| cisco | cisco_nx-os_software | >= unspecified < 8.3(2) | 8.3(2) |
| cisco | cisco_nx-os_software | >= unspecified < 7.0(3)I7(3) | 7.0(3)I7(3) |
| cisco | cisco_nx-os_software | >= unspecified < 9.2(1) | 9.2(1) |
| cisco | nx-os | < 6.0\(2\)a8\(11\) | 6.0\(2\)a8\(11\) |
| cisco | nx-os | < 7.3\(4\)n1\(1\) | 7.3\(4\)n1\(1\) |
| cisco | nx-os | < 6.2\(22\) | 6.2\(22\) |
| cisco | nx-os | < 4.0\(1d\) | 4.0\(1d\) |
| cisco | nx-os | — | — |
| cisco | nx-os | >= 5.2 < 6.2\(25\) | 6.2\(25\) |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)i7\(3\) | 7.0\(3\)i7\(3\) |
| cisco | nx-os | >= 7.0\(3\)i7 < 7.0\(3\)i7\(3\) | 7.0\(3\)i7\(3\) |
| cisco | nx-os | >= 7.2 < 7.3\(3\)d1\(1\) | 7.3\(3\)d1\(1\) |
| cisco | nx-os | >= 7.3 < 8.3\(2\) | 8.3\(2\) |
| cisco | nx-os | >= 8.0 < 8.3\(2\) | 8.3\(2\) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf5v-h8cw-pwgf: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted
ghsa_unreviewed·2022-05-24
CVE-2019-1726 [HIGH] GHSA-vf5v-h8cw-pwgf: A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability.
Cisco
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
vendor_cisco·2019-05-16·CVSS 5.3
CVE-2019-1726 [MEDIUM] CWE-78 Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API.
The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability
Cisco
Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1726 Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
CVE-2019-1726: Cisco NX-OS Software CLI Bypass to Internal Service Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient validation of arguments passed to a certain CLI command. An attacker could exploit this vulnerability by including malicious input as the argument to the affected command. A successful exploit could allow the attacker to bypass intended restrictions and access internal services of the device. An attacker would need valid device credentials to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-78, CWE-78
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-15
Published