CVE-2022-20650: Cisco NX-OS Software NX-API Command Injection Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco NX-OS vulnerability?
The vulnerability ID of this Cisco NX-OS vulnerability is CVE-2022-20650.
What is the severity level of CVE-2022-20650?
The severity level of CVE-2022-20650 is critical.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending malicious input data to the NX-API feature of Cisco NX-OS Software.
What is the affected software?
The affected software is Cisco NX-OS 10.2(1.72) and Cisco NX-OS 7.3(8)n1(0.4).
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-nxapi-cmdinject-ULukNMZ2