Home

Description

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.

PUBLISHED Reserved 2022-10-27 | Published 2023-02-23 | Updated 2024-10-25 | Assigner cisco




MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-78

Product status

Any version
affected

References

sec.cloudapps.cisco.com/...sco-sa-nxos-cli-cmdinject-euQVK9u (20230222 Cisco NX-OS Software CLI Command Injection Vulnerability) vendor-advisory

sec.cloudapps.cisco.com/...sco-sa-nxos-cli-cmdinject-euQVK9u (20230222 Cisco NX-OS Software CLI Command Injection Vulnerability) vendor-advisory

cve.org (CVE-2023-20050)

nvd.nist.gov (CVE-2023-20050)

Download JSON