CVE-2019-1603
Published: Mar 8, 2019
Modified: Nov 20, 2024
CVSS v3.0
7.8
Description
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. A successful exploit could allow an attacker to make configuration changes to the system as administrator. Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).
| Vendor | Product | Versions |
|---|---|---|
Cisco | Nexus 3000 Series Switches | affected unspecified - < 7.0(3)I7(4) |
Cisco | Nexus 3500 Platform Switches | affected unspecified - < 7.0(3)I7(4) |
Cisco | Nexus 3600 Platform Switches | affected unspecified - < 7.0(3)F3(5) |
Cisco | Nexus 9000 Series Switches-Standalone | affected unspecified - < 7.0(3)I7(4) |
Cisco | Nexus 9500 R-Series Line Cards and Fabric Modules | affected unspecified - < 7.0(3)F3(5) |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now