漏洞标题
思科NX-OS软件命令注入漏洞
漏洞描述信息
Cisco NX-OS软件CLI中存在一个漏洞,该漏洞可能允许具有管理员凭证的认证的本地攻击者在受影响设备的底层操作系统上以提升的权限执行任意命令。该漏洞是由于对某些CLI命令传递的参数验证不足导致的。攻击者可以通过将恶意输入作为受影响命令的参数来利用此漏洞。成功的利用可能允许攻击者在底层操作系统上以提升的权限执行任意命令。攻击者需要有效的管理员凭据才能利用此漏洞。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Cisco NX-OS Software Command Injection Vulnerability
漏洞描述信息
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability.
CVSS信息
N/A
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)
漏洞标题
Cisco NX-OS Software 命令参数注入漏洞
漏洞描述信息
Cisco NX-OS Software是美国思科(Cisco)公司的一套交换机使用的数据中心级操作系统软件。 Cisco NX-OS Software中的CLI存在命令参数注入漏洞。该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。以下产品及版本受到影响:Cisco MDS 9000 Series Multilayer Switches;Nexus 3000 Series Switches;Nexus 3500 Platform Swit
CVSS信息
N/A
漏洞类别
授权问题