CVE-2019-1611
Cisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with elevated privileges. An attacker would need valid administrator credentials to exploit this vulnerability. Firepower 4100 Series Next-Generation Firewalls are affected running software versions prior to 2.2.2.91, 2.3.1.110, and 2.4.1.222. Firepower 9300 Security Appliance are affected running software versions prior to 2.2.2.91, 2.3.1.110, and 2.4.1.222. MDS 9000 Series Multilayer Switches are affected running software versions prior to 6.2(25) and 8.3(1). Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(5). Nexus 3500 Platform Switches are affected running software versions prior to 7.0(3)I7(5). Nexus 3600 Platform Switches are affected running software versions prior to 7.0(3)F3(5). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected running software versions prior to 7.1(5)N1(1b) and 7.3(4)N1(1). Nexus 7000 and 7700 Series Switches are affected running software versions prior to 6.2(22), 7.3(3)D1(1), 8.2(3). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I4(9) and 7.0(3)I7(5). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5).
Una vulnerabilidad en la CLI del software NX-OS de Cisco y de Cisco FXOS podría permitir a un atacante local autenticado ejecutar comandos arbitrarios en el sistema operativo subyacente de un dispositivo afectado. La vulnerabilidad se debe a una validación de argumentos insuficiente que se envían a determinados comandos CLI. Un atacante podría explotar esta vulnerabilidad incluyendo entradas maliciosas como el argumento de un comando afectado. Un exploit con éxito podría permitir al atacante ejecutar comandos arbitrarios en el sistema operativo subyacente con privilegios elevados. Un atacante necesitaría credenciales del administrador válidas para explotar esta vulnerabilidad. Firepower 4100 Series Next-Generation Firewalls se ven afectados en versiones anteriores a las 2.2.2.91, 2.3.1.110 y 2.4.1.222. Firepower 9300 Security Appliances se ven afectados en versiones anteriores a las 2.2.2.91, 2.3.1.110 y 2.4.1.222. Los switches de MDS 9000 Series Multilayer se ven afectados en versiones anteriores a las 6.2(25) y 8.3(1). Los switches de Nexus 3000 Series se ven afectados en versiones de software anteriores a las 7.0(3)I4(9) y 7.0(3)I7(5). Los switches de Nexus 3500 Platform se ven afectados en versiones de software anteriores a la 7.0(3)I7(5). Los switches de Nexus 3600 Platform se ven afectados en versiones de software anteriores a la 7.0(3)F3(5). Los switches de Nexus, en sus series 2000, 5500, 5600 y 6000, se ven afectados en versiones anteriores a las 7.1(5)N1(1b) y 7.3(4)N1(1). Los switches de Nexus, en sus series 7000 y 7700, se ven afectados en versiones anteriores a las 6.2(22), 7.3(3)D1(1) y 8.2(3). Los switches de Nexus 9000 en modo Standalone NX-OS se ven afectados en versiones de software anteriores a las 7.0(3)I4(9) y 7.0(3)I7(5). Los switches de 9500 R-Series Line Cards y Fabric Modules se ven afectados en versiones anteriores a la 7.0(3)F3(5).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-06 CVE Reserved
- 2019-03-11 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107381 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.3 < 8.3\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.3 < 8.3\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Mds 9000 Search vendor "Cisco" for product "Mds 9000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 5.2 < 6.2\(25\) Search vendor "Cisco" for product "Nx-os" and version " >= 5.2 < 6.2\(25\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Mds 9000 Search vendor "Cisco" for product "Mds 9000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)i5 < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 3000 Search vendor "Cisco" for product "Nexus 3000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.0\(3\)i4\(9\) Search vendor "Cisco" for product "Nx-os" and version " < 7.0\(3\)i4\(9\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 3000 Search vendor "Cisco" for product "Nexus 3000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\) < 7.0\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\) < 7.0\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 3500 Search vendor "Cisco" for product "Nexus 3500" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(4\)n1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(4\)n1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 2000 Search vendor "Cisco" for product "Nexus 2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(4\)n1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(4\)n1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 5500 Search vendor "Cisco" for product "Nexus 5500" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(4\)n1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(4\)n1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 5600 Search vendor "Cisco" for product "Nexus 5600" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(4\)n1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(4\)n1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 6000 Search vendor "Cisco" for product "Nexus 6000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 6.2\(22\) Search vendor "Cisco" for product "Nx-os" and version " < 6.2\(22\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7000 Search vendor "Cisco" for product "Nexus 7000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 6.2\(22\) Search vendor "Cisco" for product "Nx-os" and version " < 6.2\(22\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7700 Search vendor "Cisco" for product "Nexus 7700" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 8.0 < 8.2\(3\) Search vendor "Cisco" for product "Nx-os" and version " >= 8.0 < 8.2\(3\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7000 Search vendor "Cisco" for product "Nexus 7000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 8.0 < 8.2\(3\) Search vendor "Cisco" for product "Nx-os" and version " >= 8.0 < 8.2\(3\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7700 Search vendor "Cisco" for product "Nexus 7700" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(3\)d1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(3\)d1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7000 Search vendor "Cisco" for product "Nexus 7000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.2 < 7.3\(3\)d1\(1\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.2 < 7.3\(3\)d1\(1\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 7700 Search vendor "Cisco" for product "Nexus 7700" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.3\(3\)i7\(5\) Search vendor "Cisco" for product "Nx-os" and version " < 7.3\(3\)i7\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 9000 Search vendor "Cisco" for product "Nexus 9000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 2.4 < 2.4.1.222 Search vendor "Cisco" for product "Fx-os" and version " >= 2.4 < 2.4.1.222" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4100 Search vendor "Cisco" for product "Firepower 4100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 2.4 < 2.4.1.222 Search vendor "Cisco" for product "Fx-os" and version " >= 2.4 < 2.4.1.222" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Search vendor "Cisco" for product "Firepower 9300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 2.3 < 2.3.1.110 Search vendor "Cisco" for product "Fx-os" and version " >= 2.3 < 2.3.1.110" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4100 Search vendor "Cisco" for product "Firepower 4100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 2.3 < 2.3.1.110 Search vendor "Cisco" for product "Fx-os" and version " >= 2.3 < 2.3.1.110" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Search vendor "Cisco" for product "Firepower 9300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 1.1 < 2.2.2.91 Search vendor "Cisco" for product "Fx-os" and version " >= 1.1 < 2.2.2.91" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 4100 Search vendor "Cisco" for product "Firepower 4100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Fx-os Search vendor "Cisco" for product "Fx-os" | >= 1.1 < 2.2.2.91 Search vendor "Cisco" for product "Fx-os" and version " >= 1.1 < 2.2.2.91" | - |
Affected
| in | Cisco Search vendor "Cisco" | Firepower 9300 Search vendor "Cisco" for product "Firepower 9300" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)f3 < 7.0\(3\)f3\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)f3 < 7.0\(3\)f3\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 3600 Search vendor "Cisco" for product "Nexus 3600" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.1\(5\)n1\(1b\) Search vendor "Cisco" for product "Nx-os" and version " < 7.1\(5\)n1\(1b\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 2000 Search vendor "Cisco" for product "Nexus 2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.1\(5\)n1\(1b\) Search vendor "Cisco" for product "Nx-os" and version " < 7.1\(5\)n1\(1b\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 5500 Search vendor "Cisco" for product "Nexus 5500" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.1\(5\)n1\(1b\) Search vendor "Cisco" for product "Nx-os" and version " < 7.1\(5\)n1\(1b\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 5600 Search vendor "Cisco" for product "Nexus 5600" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | < 7.1\(5\)n1\(1b\) Search vendor "Cisco" for product "Nx-os" and version " < 7.1\(5\)n1\(1b\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 6000 Search vendor "Cisco" for product "Nexus 6000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Nx-os Search vendor "Cisco" for product "Nx-os" | >= 7.0\(3\)f1 < 7.3\(3\)f3\(5\) Search vendor "Cisco" for product "Nx-os" and version " >= 7.0\(3\)f1 < 7.3\(3\)f3\(5\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Nexus 9500 Search vendor "Cisco" for product "Nexus 9500" | - | - |
Safe
|