Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-1600— Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability

EPSS 0.12% · P31
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-1600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco FXOS and NX-OS Software Unauthorized Directory Access Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system. The vulnerability is due to improper implementation of file system permissions. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow the attacker to access sensitive and critical files. Firepower 4100 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. Firepower 9300 Series Next-Generation Firewalls are affected in versions prior to 2.2.2.91 and 2.3.1.110. MDS 9000 Series Multilayer Switches are affected in versions prior to 6.2(25), 8.1(1b), and 8.3(1). Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected in versions prior to 7.1(5)N1(1b) and 7.3(3)N1(1). Nexus 7000 and 7700 Series Switches are affected in versions prior to 6.2(22), 7.3(3)D1(1), and 8.2(3). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
权限、特权和访问控制
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco NX-OS Software和Cisco FXOS Software 权限存在权限许可和访问控制漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Firepower 4100 Series Next-Generation Firewalls等都是美国思科(Cisco)公司的产品。Cisco Firepower 4100 Series Next-Generation Firewalls是一款4100系列的防火墙设备。Cisco FXOS Software是一套运行在思科安全设备中的防火墙软件。Cisco Nexus 3000 Series Switches是一款3000系列交换机。Cisco MDS 9000 Series Multila
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoFirepower 4100 Series Next-Generation Firewalls unspecified ~ 2.2.2.91 -
CiscoFirepower 9300 Series Next-Generation Firewalls unspecified ~ 2.2.2.91 -
CiscoMDS 9000 Series Multilayer Switches unspecified ~ 6.2(25) -
CiscoNexus 3000 Series Switches unspecified ~ 7.0(3)I4(9) -
CiscoNexus 3500 Platform Switches unspecified ~ 6.0(2)A8(10) -
CiscoNexus 3600 Platform Switches unspecified ~ 7.0(3)F3(5) -
CiscoNexus 2000, 5500, 5600, and 6000 Series Switches unspecified ~ 7.1(5)N1(1b) -
CiscoNexus 7000 and 7700 Series Switches unspecified ~ 6.2(22) -
CiscoNexus 9000 Series Switches-Standalone unspecified ~ 7.0(3)I4(9) -
CiscoNexus 9500 R-Series Line Cards and Fabric Modules unspecified ~ 7.0(3)F3(5) -

II. Public POCs for CVE-2019-1600

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1600

登录查看更多情报信息。

Same Patch Batch · Cisco · 2019-03-07 · 5 CVEs total

CVE-2019-1596Cisco NX-OS Software Bash Shell Privilege Escalation Vulnerability
CVE-2019-1597Cisco FXOS and NX-OS Lightweight Directory Access Protocol Denial of Service Vulnerabiliti
CVE-2019-1598Cisco FXOS and NX-OS Lightweight Directory Access Protocol Denial of Service Vulnerabiliti
CVE-2019-1599Cisco NX-OS Software Netstack Denial of Service Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2019-1600

No comments yet


Leave a comment