CVE-2019-1779: Cisco FXOS and NX-OS Software Command Injection Vulnerability
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid device credentials to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1779?
CVE-2019-1779 has been rated as a high-severity vulnerability due to its potential for arbitrary command execution with elevated privileges.
How do I fix CVE-2019-1779?
To mitigate CVE-2019-1779, it is recommended to upgrade the affected Cisco FXOS and NX-OS software to the latest patched versions.
Who is affected by CVE-2019-1779?
CVE-2019-1779 affects devices running certain versions of Cisco FXOS and NX-OS software that do not adequately validate input in the command-line interface.
What types of devices are impacted by CVE-2019-1779?
Devices such as Cisco Firepower series and several Cisco Nexus switches with affected NX-OS versions are impacted by CVE-2019-1779.
Is CVE-2019-1779 being actively exploited?
As of now, there are no confirmed active exploits reported for CVE-2019-1779, but the vulnerability presents significant risk if not addressed.