ID

VAR-201602-0068


CVE

CVE-2016-1341


TITLE

Cisco Nexus 2000 Fabric Extender Run on device Cisco NX-OS Vulnerability gained in

Trust: 0.8

sources: JVNDB: JVNDB-2016-001687

DESCRIPTION

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079. Vendors have confirmed this vulnerability Bug ID CSCur22079 It is released as.Authority may be obtained by local users. Cisco NX-OS is a data center-class operating system from Cisco Systems, Inc. that reflects modular design, resiliency, and maintainability. The vulnerability is caused by the program not setting a password for the root account. A local attacker could exploit this vulnerability to gain privileges. The following releases are affected: Cisco NX-OS Release 7.0(1)N1(1), Release 7.0(1)N1(3), Release 7.0(4)N1(1)

Trust: 2.25

sources: NVD: CVE-2016-1341 // JVNDB: JVNDB-2016-001687 // CNVD: CNVD-2016-01317 // VULHUB: VHN-90160

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-01317

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion:7.0\(1\)n1\(3\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:7.0\(1\)n1\(1\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:7.0\(4\)n1\(1\)

Trust: 1.6

vendor:ciscomodel:nx-osscope:eqversion:7.0(1)n1(1)

Trust: 0.8

vendor:ciscomodel:nx-osscope:eqversion:7.0(1)n1(3)

Trust: 0.8

vendor:ciscomodel:nx-osscope:eqversion:7.0(4)n1(1)

Trust: 0.8

vendor:ciscomodel:nexus seriesscope:eqversion:2000

Trust: 0.6

sources: CNVD: CNVD-2016-01317 // JVNDB: JVNDB-2016-001687 // CNNVD: CNNVD-201602-448 // NVD: CVE-2016-1341

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-1341
value: CRITICAL

Trust: 1.0

NVD: CVE-2016-1341
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2016-01317
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201602-448
value: MEDIUM

Trust: 0.6

VULHUB: VHN-90160
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-1341
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2016-01317
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-90160
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-1341
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.0

sources: CNVD: CNVD-2016-01317 // VULHUB: VHN-90160 // JVNDB: JVNDB-2016-001687 // CNNVD: CNNVD-201602-448 // NVD: CVE-2016-1341

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-90160 // JVNDB: JVNDB-2016-001687 // NVD: CVE-2016-1341

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201602-448

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201602-448

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-001687

PATCH

title:cisco-sa-20160223-nx2000url:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160223-nx2000

Trust: 0.8

title:Patch for Cisco NX-OS Privilege Escalation Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/71922

Trust: 0.6

sources: CNVD: CNVD-2016-01317 // JVNDB: JVNDB-2016-001687

EXTERNAL IDS

db:NVDid:CVE-2016-1341

Trust: 3.1

db:SECTRACKid:1035088

Trust: 1.1

db:JVNDBid:JVNDB-2016-001687

Trust: 0.8

db:CNNVDid:CNNVD-201602-448

Trust: 0.7

db:BIDid:83358

Trust: 0.6

db:CNVDid:CNVD-2016-01317

Trust: 0.6

db:VULHUBid:VHN-90160

Trust: 0.1

sources: CNVD: CNVD-2016-01317 // VULHUB: VHN-90160 // JVNDB: JVNDB-2016-001687 // CNNVD: CNNVD-201602-448 // NVD: CVE-2016-1341

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160223-nx2000

Trust: 2.3

url:http://www.securitytracker.com/id/1035088

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1341

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1341

Trust: 0.8

sources: CNVD: CNVD-2016-01317 // VULHUB: VHN-90160 // JVNDB: JVNDB-2016-001687 // CNNVD: CNNVD-201602-448 // NVD: CVE-2016-1341

SOURCES

db:CNVDid:CNVD-2016-01317
db:VULHUBid:VHN-90160
db:JVNDBid:JVNDB-2016-001687
db:CNNVDid:CNNVD-201602-448
db:NVDid:CVE-2016-1341

LAST UPDATE DATE

2024-11-23T22:34:51.139000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-01317date:2016-02-26T00:00:00
db:VULHUBid:VHN-90160date:2016-12-06T00:00:00
db:JVNDBid:JVNDB-2016-001687date:2016-03-14T00:00:00
db:CNNVDid:CNNVD-201602-448date:2016-02-25T00:00:00
db:NVDid:CVE-2016-1341date:2024-11-21T02:46:13.080

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-01317date:2016-02-26T00:00:00
db:VULHUBid:VHN-90160date:2016-02-24T00:00:00
db:JVNDBid:JVNDB-2016-001687date:2016-03-14T00:00:00
db:CNNVDid:CNNVD-201602-448date:2016-02-25T00:00:00
db:NVDid:CVE-2016-1341date:2016-02-24T03:59:01.087