CVE-2017-6649: Input Validation
A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command. An exploit could allow the attacker to read or write arbitrary files at the user's privilege level outside of the user's path. Cisco Bug IDs: CSCvb86787, CSCve60516, CSCve60555.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6649?
CVE-2017-6649 has a high severity rating due to the potential for command injection attacks on affected Cisco NX-OS versions.
How do I fix CVE-2017-6649?
To address CVE-2017-6649, upgrading to a fixed version of NX-OS that addresses the vulnerability is recommended.
What affected versions are there for CVE-2017-6649?
CVE-2017-6649 affects Cisco NX-OS versions 7.1 through 7.3.
Can unprivileged users exploit CVE-2017-6649?
No, CVE-2017-6649 requires an authenticated, local attacker to exploit the vulnerability.
What types of devices are impacted by CVE-2017-6649?
CVE-2017-6649 impacts Cisco Nexus Series Switches running vulnerable NX-OS versions.