CVE-2019-1769: Cisco NX-OS Software Line Card Command Injection Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system of an attached line card with the privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command on the affected device. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system of an attached line card with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1769?
CVE-2019-1769 is a vulnerability in the CLI of Cisco NX-OS Software that allows an authenticated local attacker to execute arbitrary commands with root privileges.
How can an attacker exploit CVE-2019-1769?
An attacker with administrator credentials can exploit CVE-2019-1769 by sending malicious commands to the affected line card.
What is the severity of CVE-2019-1769?
CVE-2019-1769 has a severity rating of 6.7, which is considered high.
Which versions of Cisco NX-OS Software are affected by CVE-2019-1769?
Cisco NX-OS Software versions up to and including 7.0(3)i7(6) are affected by CVE-2019-1769.
How can I fix CVE-2019-1769?
To mitigate the vulnerability, Cisco recommends upgrading to a fixed software release.