MEDIUM · 6.4

CVE-2019-1732

A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-u...

Vulnerability Description

A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to arbitrary command injection. The vulnerability is due to the lack of a proper locking mechanism on critical variables that need to stay static until used. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a set of RPM-related CLI commands. A successful exploit could allow the attacker to perform arbitrary command injection. The attacker would need administrator credentials for the targeted device.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoNx-Os>= 7.0\(3\)i4, < 7.0\(3\)i7\(4\)
CiscoNexus 3000-
CiscoNexus 3100-
CiscoNexus 3100-Z-
CiscoNexus 3100V-
CiscoNexus 3200-
CiscoNexus 3400-
CiscoNexus 3500-
CiscoNexus 3524-X-
CiscoNexus 3524-Xl-
CiscoNexus 3548-X-
CiscoNexus 3548-Xl-
CiscoNexus 9000-
CiscoNexus 9200-
CiscoNexus 9300-
CiscoNexus 9500-
CiscoNx Os>= 7.0\(3\), < 7.0\(3\)f3\(5\)
CiscoNexus 3600-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1732?

CVE-2019-1732 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-u...

How severe is CVE-2019-1732?

CVE-2019-1732 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1732?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Nexus 3000, Cisco Nexus 3100, Cisco Nexus 3100-Z, Cisco Nexus 3100V.