7.2

CVE-2019-1728

A vulnerability in the Secure Configuration Validation functionality of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to run arbitrary commands at system boot time with the privileges of root. The vulnerability is due to a lack of proper validation of system files when the persistent configuration information is read from the file system. An attacker could exploit this vulnerability by authenticating to the device and overwriting the persistent configuration storage with malicious executable files. An exploit could allow the attacker to run arbitrary commands at system startup and those commands will run as the root user. The attacker must have valid administrative credentials for the device.

Data is provided by the National Vulnerability Database (NVD)
CiscoNx-os Version >= 8.1 < 8.1\(1b\)
   CiscoMds 9000 Version-
   CiscoMds 9100 Version-
   CiscoMds 9200 Version-
   CiscoMds 9500 Version-
   CiscoMds 9700 Version-
CiscoNx-os Version >= 8.2 < 8.3\(1\)
   CiscoMds 9000 Version-
   CiscoMds 9100 Version-
   CiscoMds 9200 Version-
   CiscoMds 9500 Version-
   CiscoMds 9700 Version-
CiscoNx-os Version >= 7.0\(3\)i7 < 7.0\(3\)i7\(3\)
   CiscoNexus 3000 Version-
   CiscoNexus 3100 Version-
   CiscoNexus 3100-z Version-
   CiscoNexus 3100v Version-
   CiscoNexus 3200 Version-
   CiscoNexus 3400 Version-
   CiscoNexus 3500 Version-
   CiscoNexus 3600 Version-
   CiscoNexus 9000 Version-
   CiscoNexus 9200 Version-
   CiscoNexus 9300 Version-
   CiscoNexus 9500 Version-
CiscoNx-os Version >= 6.0\(2\)a8 < 6.0\(2\)a8\(11\)
   CiscoNexus 3524-x Version-
   CiscoNexus 3524-xl Version-
   CiscoNexus 3548-x Version-
   CiscoNexus 3548-xl Version-
CiscoNx-os Version >= 7.0\(3\) < 7.0\(3\)i7\(3\)
   CiscoNexus 3524-x Version-
   CiscoNexus 3524-xl Version-
   CiscoNexus 3548-x Version-
   CiscoNexus 3548-xl Version-
CiscoNx-os Version >= 7.3 < 7.3\(4\)n1\(1\)
   CiscoNexus 5500 Version-
   CiscoNexus 5600 Version-
   CiscoNexus 6000 Version-
CiscoNx-os Version >= 6.2 < 6.2\(22\)
   CiscoNexus 7000 Version-
   CiscoNexus 7700 Version-
CiscoNx-os Version >= 7.2 < 7.3\(3\)d1\(1\)
   CiscoNexus 7000 Version-
   CiscoNexus 7700 Version-
CiscoNx-os Version >= 8.0 < 8.3\(1\)
   CiscoNexus 7000 Version-
   CiscoNexus 7700 Version-
CiscoNx-os Version >= 4.0 < 4.0\(1a\)
   CiscoUcs 6248up Version-
   CiscoUcs 6296up Version-
   CiscoUcs 6332 Version-
   CiscoUsc 6324 Version-
   CiscoUsc 6332-16up Version-
CiscoNx-os Version >= 2.4 < 2.4.1.101
   CiscoFirepower 4110 Version-
   CiscoFirepower 4115 Version-
   CiscoFirepower 4120 Version-
   CiscoFirepower 4125 Version-
   CiscoFirepower 4140 Version-
   CiscoFirepower 4145 Version-
   CiscoFirepower 4150 Version-
   CiscoFirepower 9300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.255
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 6.7 0.8 5.9
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.