Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1593


A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerability.


Published

2019-03-06T22:29:00.293

Last Modified

2024-11-21T04:36:52.720

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-264
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os < 7.0\(3\)i7\(4\) Yes
Hardware cisco nexus_3000 - No
Operating System cisco nx-os < 7.0\(3\)i4\(9\) Yes
Hardware cisco nexus_3000 - No
Operating System cisco nx-os < 7.0\(3\)i7\(4\) Yes
Hardware cisco nexus_3500 - No
Operating System cisco nx-os < 7.0\(3\)f3\(5\) Yes
Hardware cisco nexus_3600 - No
Operating System cisco nx-os < 8.2\(3\) Yes
Operating System cisco nx-os < 8.3\(1\) Yes
Hardware cisco nexus_7000 - No
Hardware cisco nexus_7700 - No
Operating System cisco nx-os < 13.2\(4d\) Yes
Operating System cisco nx-os < 14.0\(1h\) Yes
Hardware cisco nexus_9000_in_aci_mode - No
Operating System cisco nx-os < 7.0\(3\)i4\(9\) Yes
Operating System cisco nx-os < 7.0\(3\)i7\(4\) Yes
Hardware cisco nexus_9000_in_standalone - No
Operating System cisco nx-os < 7.0\(3\)f3\(5\) Yes
Hardware cisco nexus_9500 * No

References