CVE-2019-1728
published 2019-05-15CVE-2019-1728: A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local…
PriorityP434medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.25%
16.6th percentile
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administrative credentials for the device.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | >= unspecified < 8.3(1) | 8.3(1) |
| cisco | fxos_and_nx-os | — | — |
| cisco | nx-os | >= 2.4 < 2.4.1.101 | 2.4.1.101 |
| cisco | nx-os | >= 4.0 < 4.0\(1a\) | 4.0\(1a\) |
| cisco | nx-os | >= 6.0\(2\)a8 < 6.0\(2\)a8\(11\) | 6.0\(2\)a8\(11\) |
| cisco | nx-os | >= 6.2 < 6.2\(22\) | 6.2\(22\) |
| cisco | nx-os | >= 7.0\(3\) < 7.0\(3\)i7\(3\) | 7.0\(3\)i7\(3\) |
| cisco | nx-os | >= 7.0\(3\)i7 < 7.0\(3\)i7\(3\) | 7.0\(3\)i7\(3\) |
| cisco | nx-os | >= 7.2 < 7.3\(3\)d1\(1\) | 7.3\(3\)d1\(1\) |
| cisco | nx-os | >= 7.3 < 7.3\(4\)n1\(1\) | 7.3\(4\)n1\(1\) |
| cisco | nx-os | >= 8.0 < 8.3\(1\) | 8.3\(1\) |
| cisco | nx-os | >= 8.1 < 8.1\(1b\) | 8.1\(1b\) |
| cisco | nx-os | >= 8.2 < 8.3\(1\) | 8.3\(1\) |
| msrc | system_center_2019_operations_manager | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
System Center Operations Manager Elevation of Privilege Vulnerability
vendor_msrc·2021-02-09·CVSS 8.8
CVE-2021-1728 [HIGH] System Center Operations Manager Elevation of Privilege Vulnerability
System Center Operations Manager Elevation of Privilege Vulnerability
FAQ: In what instances do I need to install the security update for this vulnerability?
This vulnerability only affects machines that have any of the following System Center 2019 - Operations Manager (SCOM) components installed:
Management Server
Microsoft Monitoring Agent
Gateway
Is there a prerequisite for installing the security update?
Yes. To apply this update, you must have Update Rollup 2 for System Center Operations Manager 2019 installed. See the How to obtain Update Rollup 2 for System Center Operations Manager 2019 section for instructions.
Do I need to install the update if I do not have "Enable Service log on" feature enabled?
No. This update is required if “Service Log on” or “Interactive Log on” is enab
Cisco
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
vendor_cisco·2019-05-15·CVSS 6.7
CVE-2019-1728 [MEDIUM] CWE-347 Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root.
The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administrative credenti
Cisco
Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1728 Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
CVE-2019-1728: Cisco FXOS and NX-OS Software Secure Configuration Bypass Vulnerability
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root . The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administr
GHSA
GHSA-27c7-fgf3-w57p: A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, loc
ghsa_unreviewed·2022-05-24
CVE-2019-1728 [HIGH] CWE-347 GHSA-27c7-fgf3-w57p: A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, loc
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administrative credentials for the device.
No detection rules found.
No public exploits indexed.
2019-05-15
Published