HIGH · 7.1

CVE-2013-1191

Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted ...

Vulnerability Description

Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.

CVSS Score

7.1

HIGH

AV:N/AC:H/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoNx-Os6.1
CiscoNexus 7000-
CiscoNexus 7000 10-Slot-
CiscoNexus 7000 18-Slot-
CiscoNexus 7000 9-Slot-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1191?

CVE-2013-1191 is a vulnerability with a CVSS score of 7.1 (HIGH). Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted ...

How severe is CVE-2013-1191?

CVE-2013-1191 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1191?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 7000, Cisco Nexus 7000 10-Slot, Cisco Nexus 7000 18-Slot, Cisco Nexus 7000 9-Slot.