CVE-2013-5556: Medium severity cisco nexus 1000 virtual edge vulnerability
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.
Affected Software
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2013-5556?
CVE-2013-5556 allows local users to gain elevated privileges on affected Cisco Nexus 1000V switches.
Which versions of Cisco Nexus 1000V are vulnerable to CVE-2013-5556?
CVE-2013-5556 impacts Cisco Nexus 1000V versions 4.2(1)SV1(5.2b) and earlier, as well as 5.2(1)SM1(5.1) for Microsoft Hyper-V.
How do I mitigate CVE-2013-5556 on my Cisco Nexus 1000V?
To mitigate CVE-2013-5556, upgrade to the fixed versions provided by Cisco according to the advisory.
Is CVE-2013-5556 still a concern for new installations of Cisco Nexus 1000V?
CVE-2013-5556 is a concern if your installation is using the vulnerable versions of the Cisco Nexus 1000V.
What should I do if my organization is affected by CVE-2013-5556?
If affected by CVE-2013-5556, immediately apply the recommended security updates and conduct a security review.