Release date:
Updated on:
Affected Systems:
Cisco NX-OS
Cisco Nexus 1000 V
Description:
--------------------------------------------------------------------------------
Bugtraq id: 61134
CVE (CAN) ID: CVE-2013-3400
Cisco Nexus 1000V series switches are a comprehensive architecture platform for virtual machines and cloud networks.
On a Cisco Nexus 1000V device, the license-installation module in the Cisco NX-OS system has a local command injection vulnerability where local attackers can execute arbitrary commands with special "install license" parameters.
<* Source: vendor
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3400
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-3400) and patches for this:
CVE-2013-3400: Cisco Nexus 1000 V License Installation Command Injection Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3400