ID

VAR-201405-0648


CVE

CVE-2014-1191


TITLE

Cisco NX-OS Virtual Device Context SSH Key Remote Privilege Escalation Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-03252

DESCRIPTION

Cisco NX-OS is a data center-class operating system that embodies modular design, resiliency, and maintainability. After a Cisco NX-OS device has multiple VDCs on the system and is configured with local authentication, there is a remote privilege elevation vulnerability in the implementation that allows an authenticated remote attacker to exploit the vulnerability through the SSH access management interface of the affected device. Tampering with the login information of the SSH key file to obtain administrative rights on another VDC.

Trust: 0.6

sources: CNVD: CNVD-2014-03252

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03252

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion:4.2(4)

Trust: 0.6

vendor:ciscomodel:nx-osscope:eqversion:4.2(3)

Trust: 0.6

vendor:ciscomodel:nx-osscope: - version: -

Trust: 0.6

vendor:ciscomodel:nx-osscope:eqversion:4.2(6)

Trust: 0.6

sources: CNVD: CNVD-2014-03252

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-03252
value: HIGH

Trust: 0.6

CNVD: CNVD-2014-03252
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-03252

PATCH

title:Patch for Cisco NX-OS Virtual Device Context SSH Key Remote Privilege Escalation Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/45872

Trust: 0.6

sources: CNVD: CNVD-2014-03252

EXTERNAL IDS

db:BIDid:67574

Trust: 0.6

db:NVDid:CVE-2014-1191

Trust: 0.6

db:CNVDid:CNVD-2014-03252

Trust: 0.6

sources: CNVD: CNVD-2014-03252

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20140521-nxos

Trust: 0.6

sources: CNVD: CNVD-2014-03252

SOURCES

db:CNVDid:CNVD-2014-03252

LAST UPDATE DATE

2022-05-04T08:44:10.408000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03252date:2014-05-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03252date:2014-05-26T00:00:00