CVE-2014-2200: High severity Cisco NX-OS vulnerability
Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2200?
The severity of CVE-2014-2200 is rated as high due to the potential for privilege escalation within multiple VDCs.
How do I fix CVE-2014-2200?
To fix CVE-2014-2200, upgrade to a fixed version of Cisco NX-OS that is 5.0(5) or later.
Who is affected by CVE-2014-2200?
CVE-2014-2200 affects Cisco Nexus 7000 devices running vulnerable versions of Cisco NX-OS prior to 5.0(5).
What causes CVE-2014-2200?
CVE-2014-2200 is caused by improper handling of SSH sessions that can enable remote authenticated users to escalate privileges across virtual device contexts.
Is there a workaround for CVE-2014-2200?
There is no known workaround for CVE-2014-2200; the only resolution is to apply the appropriate software update.