Release date:
Updated on:
Affected Systems:
Cisco NX-OS
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64450
CVE (CAN) ID: CVE-2012-4135
Cisco NX-OS is a data center-Level Operating System.
The command line interface of Cisco NX-OS Software has a security vulnerability. authenticated local attackers can exploit this vulnerability to execute directory traversal attacks through the filesys delete command, delete any files on the affected device.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4135? Vs_f = Cisco % 20 Security % 20 Notice & vs_cat = Security % 20 Intelligence & vs_type = RSS & vs_p = Cisco % 20NX-OS % 20 Directory % 20 Traversal % 20 Vulnerability & vs_k = 1
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cisco.com/go/psirt