Vulnerability Description
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrator rights to gain elevated privileges as the root user on an affected device. The vulnerability is due to overly permissive file permissions of specific system files. An attacker could exploit this vulnerability by authenticating to an affected device, creating a crafted command string, and writing this crafted string to a specific file location. A successful exploit could allow the attacker to execute arbitrary operating system commands as root on an affected device. The attacker would need to have valid administrator credentials for the device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nexus 9000 Series Application Centric Infrastructure | - |
| Cisco | Nexus 93108Tc-Ex | - |
| Cisco | Nexus 93120Tx | - |
| Cisco | Nexus 93128Tx | - |
| Cisco | Nexus 93180Lc-Ex | - |
| Cisco | Nexus 93180Tc-Ex | - |
| Cisco | Nexus 93180Yc-Ex | - |
| Cisco | Nexus 93180Yc-Fx | - |
| Cisco | Nexus 9332Pq | - |
| Cisco | Nexus 9336C-Fx2 | - |
| Cisco | Nexus 9336Pq Aci Spine | - |
| Cisco | Nexus 9348Gc-Fxp | - |
| Cisco | Nexus 9364C | - |
| Cisco | Nexus 9372Px | - |
| Cisco | Nexus 9372Px-E | - |
| Cisco | Nexus 9372Tx | - |
| Cisco | Nexus 9372Tx-E | - |
| Cisco | Nexus 9396Px | - |
| Cisco | Nexus 9396Tx | - |
| Cisco | Nexus 9504 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-1803?
CVE-2019-1803 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrat...
How severe is CVE-2019-1803?
CVE-2019-1803 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1803?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nexus 9000 Series Application Centric Infrastructure, Cisco Nexus 93108Tc-Ex, Cisco Nexus 93120Tx, Cisco Nexus 93128Tx, Cisco Nexus 93180Lc-Ex.