7.8

CVE-2019-1593

Cisco NX-OS Software Bash Shell Role-Based Access Control Bypass Privilege Escalation Vulnerability

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version >= 7.0\(3\)i5 < 7.0\(3\)i7\(4\)
   Cisco ≫ Nexus 3000 Version -
Cisco ≫ Nx-os Version >= 7.0\(3\)i4 < 7.0\(3\)i4\(9\)
   Cisco ≫ Nexus 3000 Version -
Cisco ≫ Nx-os Version >= 7.0\(3\) < 7.0\(3\)i7\(4\)
   Cisco ≫ Nexus 3500 Version -
Cisco ≫ Nx-os Version >= 7.0\(3\) < 7.0\(3\)f3\(5\)
   Cisco ≫ Nexus 3600 Version -
Cisco ≫ Nx-os Version >= 8.1 < 8.2\(3\)
   Cisco ≫ Nexus 7000 Version -
   Cisco ≫ Nexus 7700 Version -
Cisco ≫ Nx-os Version >= 8.3 < 8.3\(1\)
   Cisco ≫ Nexus 7000 Version -
   Cisco ≫ Nexus 7700 Version -
Cisco ≫ Nx-os Version < 13.2\(4d\)
   Cisco ≫ Nexus 9000 In Aci Mode Version -
Cisco ≫ Nx-os Version >= 14.0 < 14.0\(1h\)
   Cisco ≫ Nexus 9000 In Aci Mode Version -
Cisco ≫ Nx-os Version >= 7.0\(3\)i4 < 7.0\(3\)i4\(9\)
   Cisco ≫ Nexus 9000 In Standalone Version -
Cisco ≫ Nx-os Version >= 7.0\(3\)i5 < 7.0\(3\)i7\(4\)
   Cisco ≫ Nexus 9000 In Standalone Version -
Cisco ≫ Nx-os Version >= 7.0\(3\) < 7.0\(3\)f3\(5\)
   Cisco ≫ Nexus 9500
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.313
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Cisco PSIRT 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/107324
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nx-os-bash-escal
Patch
Vendor Advisory