Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1803


A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrator rights to gain elevated privileges as the root user on an affected device. The vulnerability is due to overly permissive file permissions of specific system files. An attacker could exploit this vulnerability by authenticating to an affected device, creating a crafted command string, and writing this crafted string to a specific file location. A successful exploit could allow the attacker to execute arbitrary operating system commands as root on an affected device. The attacker would need to have valid administrator credentials for the device.


Published

2019-05-03T17:29:00.737

Last Modified

2024-11-21T04:37:24.733

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-264
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nexus_9000_series_application_centric_infrastructure - Yes
Hardware cisco nexus_93108tc-ex - No
Hardware cisco nexus_93120tx - No
Hardware cisco nexus_93128tx - No
Hardware cisco nexus_93180lc-ex - No
Hardware cisco nexus_93180tc-ex - No
Hardware cisco nexus_93180yc-ex - No
Hardware cisco nexus_93180yc-fx - No
Hardware cisco nexus_9332pq - No
Hardware cisco nexus_9336c-fx2 - No
Hardware cisco nexus_9336pq_aci_spine - No
Hardware cisco nexus_9348gc-fxp - No
Hardware cisco nexus_9364c - No
Hardware cisco nexus_9372px - No
Hardware cisco nexus_9372px-e - No
Hardware cisco nexus_9372tx - No
Hardware cisco nexus_9372tx-e - No
Hardware cisco nexus_9396px - No
Hardware cisco nexus_9396tx - No
Hardware cisco nexus_9504 - No
Hardware cisco nexus_9508 - No
Hardware cisco nexus_9516 - No

References