CVE-2019-1781: Cisco FXOS and NX-OS Software Command Injection Vulnerability
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need administrator credentials to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1781?
The severity of CVE-2019-1781 is classified as critical due to its potential to allow authenticated local attackers to execute arbitrary commands.
How do I fix CVE-2019-1781?
To fix CVE-2019-1781, upgrade your Cisco FXOS Software or NX-OS Software to the latest patched version recommended by Cisco.
Which Cisco devices are affected by CVE-2019-1781?
CVE-2019-1781 affects certain versions of Cisco FXOS Software and NX-OS Software; specific device models include Cisco Nexus and Cisco UCS series.
What types of attacks can CVE-2019-1781 facilitate?
CVE-2019-1781 can facilitate command injection attacks allowing attackers to execute malicious commands on vulnerable devices.
When was CVE-2019-1781 disclosed?
CVE-2019-1781 was disclosed on May 15, 2019, by Cisco in a security advisory.