Vulnerability Description
Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AAA restrictions and obtain privileged CLI access via crafted parameters in an SSH connection negotiation, aka Bug IDs CSCum35502, CSCuw78669, CSCuw79754, and CSCux88492.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 4.1.\(2\) |
| Cisco | Nexus 7000 10-Slot | - |
| Cisco | Nexus 7000 18-Slot | - |
| Cisco | Nexus 7000 4-Slot | - |
| Cisco | Nexus 7000 9-Slot | - |
| Cisco | Nexus 7700 10-Slot | - |
| Cisco | Nexus 7700 18-Slot | - |
| Cisco | Nexus 7700 2-Slot | - |
| Cisco | Nexus 7700 6-Slot | - |
| Cisco | Nexus 4001I | - |
| Cisco | Nexus 5010 | - |
| Cisco | Nexus 5020 | - |
| Cisco | Nexus 5548P | - |
| Cisco | Nexus 5548Up | - |
| Cisco | Nexus 5596T | - |
| Cisco | Nexus 5596Up | - |
| Cisco | Nexus 56128P | - |
| Cisco | Nexus 5624Q | - |
| Cisco | Nexus 5648Q | - |
| Cisco | Nexus 5672Up | - |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/93410
- http://www.securitytracker.com/id/1036947
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securityfocus.com/bid/93410
- http://www.securitytracker.com/id/1036947
FAQ
What is CVE-2015-0721?
CVE-2015-0721 is a vulnerability with a CVSS score of 8.0 (HIGH). Cisco NX-OS 4.0 through 7.3 on Multilayer Director and Nexus 1000V, 2000, 3000, 3500, 4000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote authenticated users to bypass intended AA...
How severe is CVE-2015-0721?
CVE-2015-0721 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0721?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 7000 10-Slot, Cisco Nexus 7000 18-Slot, Cisco Nexus 7000 4-Slot, Cisco Nexus 7000 9-Slot.