CVE-2017-6650
Description
A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into the Telnet CLI command. An exploit could allow the attacker to read or write arbitrary files at the users privilege level outside of the users path. Cisco Bug IDs: CSCvb86771.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.577
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Cisco Nexus Series Switches Telnet CLI Command Injection Vulnerability For Cisco NX-OS Software | NCM |
| Improper Input Validation Vulnerability (CVE-2017-6650) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1706149 | Security Update for Cisco NX-OS Software 4.1(3a)UCSM |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234