CVE-2022-20909
Cisco Nexus Dashboard Privilege Escalation Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by authenticating as the rescue-user and executing vulnerable CLI commands using a malicious payload. A successful exploit could allow the attacker to elevate privileges to root on an affected device.
Múltiples vulnerabilidades en Cisco Nexus Dashboard podrían permitir a un atacante local autenticado elevar los privilegios en un dispositivo afectado. Estas vulnerabilidades son debido a que no son comprobados suficientemente las entradas durante la ejecución de comandos de la CLI en un dispositivo afectado. Un atacante podría explotar estas vulnerabilidades autenticándose como usuario de rescate y ejecutando comandos CLI vulnerables usando una carga útil maliciosa. Una explotación con éxito podría permitir al atacante elevar los privilegios a root en un dispositivo afectado
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-11-02 CVE Reserved
- 2022-07-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Nexus Dashboard Search vendor "Cisco" for product "Nexus Dashboard" | >= 2.0 < 2.2\(1e\) Search vendor "Cisco" for product "Nexus Dashboard" and version " >= 2.0 < 2.2\(1e\)" | - |
Affected
|