Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-1734— Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability

EPSS 0.20% · P42
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-1734

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco FXOS and NX-OS Software Sensitive File Read Information Disclosure Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based access control (RBAC) verification. An attacker could exploit this vulnerability by authenticating to the device and issuing a specific CLI diagnostic command with crafted user-input parameters. An exploit could allow the attacker to perform an arbitrary read of a file on the device, and the file may contain sensitive information. The attacker needs valid device credentials to exploit this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco FXOS Software和Cisco NX-OS Software 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Firepower 4100 Series等都是美国思科(Cisco)公司的产品。Cisco Firepower 4100 Series是一款4100系列的防火墙设备。Cisco Firepower 9300 Security Appliance是一款9300系列的安全设备。Cisco FXOS Software是一套运行在思科安全设备中的防火墙软件。Cisco MDS 9000 Series Multilayer Switches是一款MDS 9000系列多层交换机。Cisco NX-OS
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco NX-OS Software unspecified ~ 6.2(7) -

II. Public POCs for CVE-2019-1734

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1734

登录查看更多情报信息。

Same Patch Batch · Cisco · 2019-11-05 · 9 CVEs total

CVE-2019-159667.7 HIGHCisco TelePresence Advanced Media Gateway 输入验证错误漏洞
CVE-2019-126257.5 HIGHClamAV Zip Bomb Vulnerability
CVE-2019-17897.5 HIGHClamAV Denial of Service Vulnerability
CVE-2019-1877Cisco Enterprise Chat and Email Attachment Download Vulnerability
CVE-2019-1978Cisco Firepower Threat Defense Software Stream Reassembly Bypass Vulnerability
CVE-2019-1980Cisco Firepower Threat Defense Software Nonstandard Protocol Detection Bypass Vulnerabilit
CVE-2019-1981Cisco Firepower Threat Defense Software NULL Character Obfuscation Detection Bypass Vulner
CVE-2019-1982Cisco Firepower Threat Defense Software HTTP Filtering Bypass Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2019-1734

No comments yet


Leave a comment