Summary
A vulnerability in the command-line interface (CLI) of Cisco NX-OS Software could allow an authenticated, local attacker to access the contents of arbitrary files on the affected device.
Impact
Exploiting this issue can allow a local attacker to gain read access to arbitrary files. Information harvested may aid in launching further attacks.
Solution
Updates are available.
Insight
This issue is being tracked by Cisco Bug ID CSCul05217 and CSCul23419
Affected
This vulnerability affects the following platforms which are based on Cisco NX-OS:
Cisco Nexus 7000
Cisco MDS 9000
Cisco Nexus 6000
Cisco Nexus 5500
Cisco Nexus 5000
Cisco Nexus 4000
Cisco Nexus 3500
Cisco Nexus 3000
Cisco Nexus 1000V
Cisco Connected Grid Router 1000 Series
Cisco Unified Computing System Fabric Interconnect 6200 Cisco Unified Computing System Fabric Interconnect 6100
Detection
Check the NX OS version.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-6975 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:S/C:C/I:N/A:N
Related Vulnerabilities
- Cisco Nexus 7000 Series Switches Remote Denial of Service Vulnerability
- Cisco NX-OS BGP Message Denial of Service Vulnerability
- Cisco Nexus 7000 Series Switches Local Denial of Service Vulnerability
- Cisco Open Network Environment Platform Denial of Service Vulnerability
- Cisco NX-OS Software Arbitrary File Read Vulnerability