7.8
CVE-2018-0306
- EPSS 0.13%
- Veröffentlicht 21.06.2018 11:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:56
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device. Note: This vulnerability requires that any feature license is uploaded to the device. The vulnerability does not require that the license be used. This vulnerability affects MDS 9000 Series Multilayer Switches, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 3600 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCve51693, CSCve91634, CSCve91659, CSCve91663.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version < 7.3\(3\)n1\(1\)
Cisco ≫ Nexus 5000 Version-
Cisco ≫ Nexus 5010 Version-
Cisco ≫ Nexus 5020 Version-
Cisco ≫ Nexus 5548p Version-
Cisco ≫ Nexus 5548up Version-
Cisco ≫ Nexus 5596t Version-
Cisco ≫ Nexus 5596up Version-
Cisco ≫ Nexus 56128p Version-
Cisco ≫ Nexus 5624q Version-
Cisco ≫ Nexus 5648q Version-
Cisco ≫ Nexus 5672up Version-
Cisco ≫ Nexus 5696q Version-
Cisco ≫ Nexus 5010 Version-
Cisco ≫ Nexus 5020 Version-
Cisco ≫ Nexus 5548p Version-
Cisco ≫ Nexus 5548up Version-
Cisco ≫ Nexus 5596t Version-
Cisco ≫ Nexus 5596up Version-
Cisco ≫ Nexus 56128p Version-
Cisco ≫ Nexus 5624q Version-
Cisco ≫ Nexus 5648q Version-
Cisco ≫ Nexus 5672up Version-
Cisco ≫ Nexus 5696q Version-
Cisco ≫ Nx-os Version8.1(0)bd(0.20)
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nx-os Version8.1(0.59)s0
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nx-os Version8.1(1)
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nx-os Version6.0(2)a8(3)
Cisco ≫ Nexus 172tq-xl Version-
Cisco ≫ Nexus 3016 Version-
Cisco ≫ Nexus 3048 Version-
Cisco ≫ Nexus 3064-32t Version-
Cisco ≫ Nexus 3064-t Version-
Cisco ≫ Nexus 3064-x Version-
Cisco ≫ Nexus 3100-v Version-
Cisco ≫ Nexus 31128pq Version-
Cisco ≫ Nexus 3132c-z Version-
Cisco ≫ Nexus 3132q Version-
Cisco ≫ Nexus 3132q-x Version-
Cisco ≫ Nexus 3132q-xl Version-
Cisco ≫ Nexus 3164q Version-
Cisco ≫ Nexus 3172pq Version-
Cisco ≫ Nexus 3172pq-xl Version-
Cisco ≫ Nexus 3172tq Version-
Cisco ≫ Nexus 3172tq-32t Version-
Cisco ≫ Nexus 3232c Version-
Cisco ≫ Nexus 3264c-e Version-
Cisco ≫ Nexus 3264q Version-
Cisco ≫ Nexus 34180yc Version-
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548 Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3636c-r Version-
Cisco ≫ Nexus C36180yc-r Version-
Cisco ≫ Nexus 3016 Version-
Cisco ≫ Nexus 3048 Version-
Cisco ≫ Nexus 3064-32t Version-
Cisco ≫ Nexus 3064-t Version-
Cisco ≫ Nexus 3064-x Version-
Cisco ≫ Nexus 3100-v Version-
Cisco ≫ Nexus 31128pq Version-
Cisco ≫ Nexus 3132c-z Version-
Cisco ≫ Nexus 3132q Version-
Cisco ≫ Nexus 3132q-x Version-
Cisco ≫ Nexus 3132q-xl Version-
Cisco ≫ Nexus 3164q Version-
Cisco ≫ Nexus 3172pq Version-
Cisco ≫ Nexus 3172pq-xl Version-
Cisco ≫ Nexus 3172tq Version-
Cisco ≫ Nexus 3172tq-32t Version-
Cisco ≫ Nexus 3232c Version-
Cisco ≫ Nexus 3264c-e Version-
Cisco ≫ Nexus 3264q Version-
Cisco ≫ Nexus 34180yc Version-
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548 Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3636c-r Version-
Cisco ≫ Nexus C36180yc-r Version-
Cisco ≫ Nx-os Version < 7.3\(3\)n1\(1\)
Cisco ≫ Nexus 2148t Version-
Cisco ≫ Nexus 2224tp Ge Version-
Cisco ≫ Nexus 2232pp 10ge Version-
Cisco ≫ Nexus 2232tm-e 10ge Version-
Cisco ≫ Nexus 2232tm 10ge Version-
Cisco ≫ Nexus 2248pq 10ge Version-
Cisco ≫ Nexus 2248tp-e Version-
Cisco ≫ Nexus 2248tp Ge Version-
Cisco ≫ Nexus 2224tp Ge Version-
Cisco ≫ Nexus 2232pp 10ge Version-
Cisco ≫ Nexus 2232tm-e 10ge Version-
Cisco ≫ Nexus 2232tm 10ge Version-
Cisco ≫ Nexus 2248pq 10ge Version-
Cisco ≫ Nexus 2248tp-e Version-
Cisco ≫ Nexus 2248tp Ge Version-
Cisco ≫ Nx-os Version < 8.1\(1a\)
Cisco ≫ Mds 9132t Version-
Cisco ≫ Mds 9148 Version-
Cisco ≫ Mds 9148s Version-
Cisco ≫ Mds 9148t Version-
Cisco ≫ Mds 9222i Version-
Cisco ≫ Mds 9250i Version-
Cisco ≫ Mds 9396s Version-
Cisco ≫ Mds 9396t Version-
Cisco ≫ Mds 9506 Version-
Cisco ≫ Mds 9509 Version-
Cisco ≫ Mds 9513 Version-
Cisco ≫ Mds 9706 Version-
Cisco ≫ Mds 9710 Version-
Cisco ≫ Mds 9718 Version-
Cisco ≫ Mds 9148 Version-
Cisco ≫ Mds 9148s Version-
Cisco ≫ Mds 9148t Version-
Cisco ≫ Mds 9222i Version-
Cisco ≫ Mds 9250i Version-
Cisco ≫ Mds 9396s Version-
Cisco ≫ Mds 9396t Version-
Cisco ≫ Mds 9506 Version-
Cisco ≫ Mds 9509 Version-
Cisco ≫ Mds 9513 Version-
Cisco ≫ Mds 9706 Version-
Cisco ≫ Mds 9710 Version-
Cisco ≫ Mds 9718 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.298 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.