First published: Fri Jul 03 2015(Updated: )
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Nx-os | =7.2\(0\)zz\(99.3\) | |
Cisco Nexus 93120tx | ||
Cisco Nexus 93128tx | ||
Cisco Nexus 9332pq | ||
Cisco Nexus 9336pq Aci Spine | ||
Cisco Nexus 9372px | ||
Cisco Nexus 9372tx | ||
Cisco Nexus 9396px | ||
Cisco Nexus 9396tx | ||
Cisco Nexus 9504 | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 | ||
Cisco Nx-os | =7.2\(0\)zz\(99.1\) | |
Cisco Nexus 3016 | ||
Cisco Nexus 3048 | ||
Cisco Nexus 3064 | ||
Cisco Nexus 3132q | ||
Cisco Nexus 3164q | ||
Cisco Nexus 3172 | ||
Cisco Nexus 3232c | ||
Cisco Nexus 3524 | ||
Cisco Nexus 3548 | ||
Cisco Nx-os | =6.2\(11b\) | |
Cisco Mds 9100 | ||
Cisco Mds 9140 | ||
Cisco Mds 9500 | ||
Cisco Mds 9700 | ||
Cisco Nx-os | =9.1\(1\)sv1\(3.1.8\) | |
Cisco Nexus 1000v | ||
Cisco Nexus 5548p | ||
Cisco Nexus 5548up | ||
Cisco Nexus 5596t | ||
Cisco Nexus 5596up | ||
Cisco Nexus 56128p | ||
Cisco Nexus 5624q | ||
Cisco Nexus 5648q | ||
Cisco Nexus 5672up | ||
Cisco Nexus 5696q | ||
Cisco Nx-os | =6.2\(12\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7700 | ||
Cisco Nx-os | =4.1\(2\)e1\(1\) | |
Cisco Nexus 4001i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.