Cisco NX-OS System Software Arbitrary File Read Vulnerability (CVE-2017-12338)
Cisco NX-OS System Software Arbitrary File Read Vulnerability (CVE-2017-12338)
Release date:
Updated on:
Affected Systems:
Cisco NX-OS
Description:
Bugtraq id: 102260
CVE (CAN) ID: CVE-2017-12338
Cisco NX-OS is a data center-Level Operating System.
Cisco NX-OS System Software has a security vulnerability in CLI implementations that allows authenticated local attackers to read arbitrary files. This vulnerability is caused by invalid input verification for specific CLI commands.
<* Source: Zhaoxin Li
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-nxos6
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20171129-nxos6) and patches for this:
Cisco-sa-20171129-nxos6: Cisco NX-OS System Software CLI Arbitrary File Read Vulnerability
Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-nxos6