First published: Wed Jul 10 2013(Updated: )
The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | ||
Cisco Nexus 1000 Virtual Edge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3400 has a high severity score due to its potential for arbitrary command execution.
Mitigation for CVE-2013-3400 involves updating the Cisco NX-OS software to a version that addresses this vulnerability.
CVE-2013-3400 affects local users of Cisco NX-OS on Nexus 1000V devices.
CVE-2013-3400 is classified as a command injection vulnerability.
There are no specific workarounds for CVE-2013-3400; the recommended action is to apply the software update.