First published: Sat May 24 2014(Updated: )
Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =5.0\(3\)n1\(1\) | |
Cisco NX-OS | =5.0\(3\)n1\(1a\) | |
Cisco NX-OS | =5.0\(3\)n1\(1b\) | |
Cisco NX-OS | =5.0\(3\)n1\(1c\) | |
Cisco NX-OS | =5.0\(3\)n2\(1\) | |
Cisco NX-OS | =5.0\(3\)n2\(2\) | |
Cisco NX-OS | =5.0\(3\)n2\(2a\) | |
Cisco NX-OS | =5.0\(3\)n2\(2b\) | |
Cisco NX-OS | =5.0\(3\)u1\(1a\) | |
Cisco NX-OS | =5.0\(3\)u1\(1b\) | |
Cisco NX-OS | =5.0\(3\)u1\(1d\) | |
Cisco NX-OS | =5.0\(3\)u1\(2\) | |
Cisco NX-OS | =5.0\(3\)u1\(2a\) | |
Cisco NX-OS | =5.0\(3\)u2\(1\) | |
Cisco NX-OS | =5.0\(3\)u2\(2\) | |
Cisco NX-OS | =5.0\(3\)u2\(2a\) | |
Cisco NX-OS | =5.0\(3\)u2\(2b\) | |
Cisco NX-OS | =5.0\(3\)u2\(2c\) | |
Cisco NX-OS | =5.0\(3\)u2\(2d\) | |
Cisco NX-OS | =5.0\(3\)u3\(1\) | |
Cisco NX-OS | =5.0\(3\)u3\(2\) | |
Cisco NX-OS | =5.0\(3\)u3\(2a\) | |
Cisco NX-OS | =5.0\(3\)u3\(2b\) | |
Cisco NX-OS | =5.0\(3\)u4\(1\) | |
Cisco NX-OS | =5.0\(3\)u5\(1\) | |
Cisco NX-OS | =5.0\(3\)u5\(1a\) | |
Cisco NX-OS | =5.0\(3\)u5\(1b\) | |
Cisco NX-OS | =5.0\(3\)u5\(1c\) | |
Cisco NX-OS | =5.0\(3\)u5\(1d\) | |
Cisco NX-OS | =5.0\(3\)u5\(1e\) | |
Cisco Nexus 7000 Series Switch | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware | ||
All of | ||
Any of | ||
Cisco NX-OS | =5.0\(3\)n1\(1\) | |
Cisco NX-OS | =5.0\(3\)n1\(1a\) | |
Cisco NX-OS | =5.0\(3\)n1\(1b\) | |
Cisco NX-OS | =5.0\(3\)n1\(1c\) | |
Cisco NX-OS | =5.0\(3\)n2\(1\) | |
Cisco NX-OS | =5.0\(3\)n2\(2\) | |
Cisco NX-OS | =5.0\(3\)n2\(2a\) | |
Cisco NX-OS | =5.0\(3\)n2\(2b\) | |
Cisco NX-OS | =5.0\(3\)u1\(1a\) | |
Cisco NX-OS | =5.0\(3\)u1\(1b\) | |
Cisco NX-OS | =5.0\(3\)u1\(1d\) | |
Cisco NX-OS | =5.0\(3\)u1\(2\) | |
Cisco NX-OS | =5.0\(3\)u1\(2a\) | |
Cisco NX-OS | =5.0\(3\)u2\(1\) | |
Cisco NX-OS | =5.0\(3\)u2\(2\) | |
Cisco NX-OS | =5.0\(3\)u2\(2a\) | |
Cisco NX-OS | =5.0\(3\)u2\(2b\) | |
Cisco NX-OS | =5.0\(3\)u2\(2c\) | |
Cisco NX-OS | =5.0\(3\)u2\(2d\) | |
Cisco NX-OS | =5.0\(3\)u3\(1\) | |
Cisco NX-OS | =5.0\(3\)u3\(2\) | |
Cisco NX-OS | =5.0\(3\)u3\(2a\) | |
Cisco NX-OS | =5.0\(3\)u3\(2b\) | |
Cisco NX-OS | =5.0\(3\)u4\(1\) | |
Cisco NX-OS | =5.0\(3\)u5\(1\) | |
Cisco NX-OS | =5.0\(3\)u5\(1a\) | |
Cisco NX-OS | =5.0\(3\)u5\(1b\) | |
Cisco NX-OS | =5.0\(3\)u5\(1c\) | |
Cisco NX-OS | =5.0\(3\)u5\(1d\) | |
Cisco NX-OS | =5.0\(3\)u5\(1e\) | |
Any of | ||
Cisco Nexus 7000 Series Switch | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 | ||
Cisco Nexus 7000 9-Slot Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2200 is rated as high due to the potential for privilege escalation within multiple VDCs.
To fix CVE-2014-2200, upgrade to a fixed version of Cisco NX-OS that is 5.0(5) or later.
CVE-2014-2200 affects Cisco Nexus 7000 devices running vulnerable versions of Cisco NX-OS prior to 5.0(5).
CVE-2014-2200 is caused by improper handling of SSH sessions that can enable remote authenticated users to escalate privileges across virtual device contexts.
There is no known workaround for CVE-2014-2200; the only resolution is to apply the appropriate software update.