CVE-2013-3400: Input Validation
Published Jul 10, 2013
·Updated
The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.
Affected Software
2 affected components
cisco NX-OS
cisco Nexus 1000V
Event History
Jul 10, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3400?
CVE-2013-3400 has a high severity score due to its potential for arbitrary command execution.
2
How can I mitigate CVE-2013-3400?
Mitigation for CVE-2013-3400 involves updating the Cisco NX-OS software to a version that addresses this vulnerability.
3
Who is affected by CVE-2013-3400?
CVE-2013-3400 affects local users of Cisco NX-OS on Nexus 1000V devices.
4
What type of vulnerability is CVE-2013-3400?
CVE-2013-3400 is classified as a command injection vulnerability.
5
Is there a workaround for CVE-2013-3400?
There are no specific workarounds for CVE-2013-3400; the recommended action is to apply the software update.