CVE-2019-1836 — Path Traversal in Cisco Nx-os Software FOR Nexus 9000 Series Fabric Switches ACI Mode
Severity
7.1HIGHNVD
EPSS
0.2%
top 56.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 24
Description
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files. These system files may be sensitive and should not be overwritable by non-root users. The attacker would need valid device credentials. The vulnerability is due to incorrect symbolic link verification of directory paths when they are used in the system shell. An attacker could…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages2 packages
▶CVEListV5cisco/cisco_nx-os_software_for_nexus_9000_series_fabric_switches_aci_modeunspecified — 14.1(1i)
🔴Vulnerability Details
2GHSA▶
GHSA-3pmp-7vwx-87p3: A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authen↗2022-05-24
CVEList▶
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Symbolic Link Path Traversal Vulnerability↗2019-05-03
📋Vendor Advisories
1Cisco▶
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Symbolic Link Path Traversal Vulnerability↗2019-05-01