7.2
CVE-2019-1728
- EPSS 0.11%
- Veröffentlicht 15.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:37:11
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administrative credentials for the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version >= 7.0\(3\)i7 < 7.0\(3\)i7\(3\)
Cisco ≫ Nexus 3000 Version-
Cisco ≫ Nexus 3100 Version-
Cisco ≫ Nexus 3100-z Version-
Cisco ≫ Nexus 3100v Version-
Cisco ≫ Nexus 3200 Version-
Cisco ≫ Nexus 3400 Version-
Cisco ≫ Nexus 3500 Version-
Cisco ≫ Nexus 3600 Version-
Cisco ≫ Nexus 9000 Version-
Cisco ≫ Nexus 9200 Version-
Cisco ≫ Nexus 9300 Version-
Cisco ≫ Nexus 9500 Version-
Cisco ≫ Nexus 3100 Version-
Cisco ≫ Nexus 3100-z Version-
Cisco ≫ Nexus 3100v Version-
Cisco ≫ Nexus 3200 Version-
Cisco ≫ Nexus 3400 Version-
Cisco ≫ Nexus 3500 Version-
Cisco ≫ Nexus 3600 Version-
Cisco ≫ Nexus 9000 Version-
Cisco ≫ Nexus 9200 Version-
Cisco ≫ Nexus 9300 Version-
Cisco ≫ Nexus 9500 Version-
Cisco ≫ Nx-os Version >= 6.0\(2\)a8 < 6.0\(2\)a8\(11\)
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nx-os Version >= 7.0\(3\) < 7.0\(3\)i7\(3\)
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nx-os Version >= 4.0 < 4.0\(1a\)
Cisco ≫ Ucs 6248up Version-
Cisco ≫ Ucs 6296up Version-
Cisco ≫ Ucs 6332 Version-
Cisco ≫ Usc 6324 Version-
Cisco ≫ Usc 6332-16up Version-
Cisco ≫ Ucs 6296up Version-
Cisco ≫ Ucs 6332 Version-
Cisco ≫ Usc 6324 Version-
Cisco ≫ Usc 6332-16up Version-
Cisco ≫ Nx-os Version >= 2.4 < 2.4.1.101
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 9300 Version-
Cisco ≫ Firepower 4115 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4125 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4145 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 9300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.255 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.