cbcvebase.
CVE-2022-20650
published 2022-02-23

CVE-2022-20650: A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges…

PriorityP270high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
14.55%
96.3th percentile
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_nx-os_software
cisconx-os
cisconx-os
cisconx-os

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP POST request sent to the NX-API endpoint of an affected Cisco NX-OS device; monitor for anomalous or unexpected POST requests to the NX-API interface
  • Successful exploitation results in arbitrary OS command execution with root privileges; alert on unexpected root-level process spawning from NX-API service processes
  • The NX-API feature is disabled by default; audit devices to confirm NX-API is not unexpectedly enabled, and restrict access to it if enabled
  • ·The NX-API feature must be explicitly enabled for this vulnerability to be exploitable; devices with NX-API disabled are not at risk
  • ·The vulnerability requires authentication; unauthenticated attackers cannot exploit this directly
  • ·Cisco Bug IDs CSCvz80191 and CSCvz81047 track this vulnerability across affected NX-OS platforms

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.