CVE-2017-6650: Input Validation
A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into the Telnet CLI command. An exploit could allow the attacker to read or write arbitrary files at the user's privilege level outside of the user's path. Cisco Bug IDs: CSCvb86771.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6650?
CVE-2017-6650 has a high severity rating due to the potential for command injection by authenticated local attackers.
How do I fix CVE-2017-6650?
To fix CVE-2017-6650, update your Cisco NX-OS software to a version that addresses the vulnerability, such as 7.3 or later.
Which Cisco NX-OS versions are affected by CVE-2017-6650?
CVE-2017-6650 affects Cisco NX-OS versions 7.1 through 7.3.
What type of attack does CVE-2017-6650 enable?
CVE-2017-6650 enables authenticated local attackers to perform command injection attacks.
Who is affected by CVE-2017-6650?
Organizations using Cisco Nexus Series Switches running affected versions of Cisco NX-OS are at risk from CVE-2017-6650.