{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-20413", "ASSIGNER": "psirt@cisco.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.\r\n\r\nThis vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Missing Authorization", "cweId": "CWE-862" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Cisco", "product": { "product_data": [ { "product_name": "Cisco NX-OS Software", "version": { "version_data": [ { "version_affected": "=", "version_value": "9.2(3)" }, { "version_affected": "=", "version_value": "7.0(3)I5(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(5)" }, { "version_affected": "=", "version_value": "6.0(2)A6(1)" }, { "version_affected": "=", "version_value": "7.0(3)I4(6)" }, { "version_affected": "=", "version_value": "7.0(3)I4(3)" }, { "version_affected": "=", "version_value": "9.2(2v)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5b)" }, { "version_affected": "=", "version_value": "7.0(3)I4(7)" }, { "version_affected": "=", "version_value": "6.0(2)U6(1a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(1)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8)" }, { "version_affected": "=", "version_value": "7.0(3)I4(2)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11)" }, { "version_affected": "=", "version_value": "6.0(2)A6(4a)" }, { "version_affected": "=", "version_value": "9.2(1)" }, { "version_affected": "=", "version_value": "9.2(2t)" }, { "version_affected": "=", "version_value": "9.2(3y)" }, { "version_affected": "=", "version_value": "7.0(3)I4(1t)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5c)" }, { "version_affected": "=", "version_value": "6.0(2)A6(4)" }, { "version_affected": "=", "version_value": "7.0(3)I7(6z)" }, { "version_affected": "=", "version_value": "9.3(2)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3)" }, { "version_affected": "=", "version_value": "6.0(2)U6(6)" }, { "version_affected": "=", "version_value": "7.0(3)I7(3z)" }, { "version_affected": "=", "version_value": "7.0(3)IM7(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11b)" }, { "version_affected": "=", "version_value": "7.0(3)I7(5a)" }, { "version_affected": "=", "version_value": "7.0(3)I6(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(10)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2)" }, { "version_affected": "=", "version_value": "6.0(2)A6(8)" }, { "version_affected": "=", "version_value": "6.0(2)U6(1)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3b)" }, { "version_affected": "=", "version_value": "6.0(2)A6(2a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(7)" }, { "version_affected": "=", "version_value": "9.2(4)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(10)" }, { "version_affected": "=", "version_value": "6.0(2)A8(2)" }, { "version_affected": "=", "version_value": "7.0(3)IC4(4)" }, { "version_affected": "=", "version_value": "6.0(2)A6(3)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5b)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3c)" }, { "version_affected": "=", "version_value": "7.0(3)F3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(5)" }, { "version_affected": "=", "version_value": "7.0(3)F3(5)" }, { "version_affected": "=", "version_value": "6.0(2)A6(7)" }, { "version_affected": "=", "version_value": "7.0(3)I7(2)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(2b)" }, { "version_affected": "=", "version_value": "6.0(2)U6(4a)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3)" }, { "version_affected": "=", "version_value": "7.0(3)I7(3)" }, { "version_affected": "=", "version_value": "6.0(2)A8(6)" }, { "version_affected": "=", "version_value": "7.0(3)I6(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(5)" }, { "version_affected": "=", "version_value": "6.0(2)U6(8)" }, { "version_affected": "=", "version_value": "7.0(3)IM3(3)" }, { "version_affected": "=", "version_value": "9.3(1)" }, { "version_affected": "=", "version_value": "6.0(2)U6(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7)" }, { "version_affected": "=", "version_value": "7.0(3)I7(6)" }, { "version_affected": "=", "version_value": "6.0(2)U6(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(11a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8z)" }, { "version_affected": "=", "version_value": "7.0(3)I4(9)" }, { "version_affected": "=", "version_value": "7.0(3)I7(4)" }, { "version_affected": "=", "version_value": "7.0(3)I7(7)" }, { "version_affected": "=", "version_value": "6.0(2)A8(9)" }, { "version_affected": "=", "version_value": "6.0(2)A8(1)" }, { "version_affected": "=", "version_value": "6.0(2)A6(6)" }, { "version_affected": "=", "version_value": "6.0(2)A8(10a)" }, { "version_affected": "=", "version_value": "7.0(3)I5(1)" }, { "version_affected": "=", "version_value": "9.3(1z)" }, { "version_affected": "=", "version_value": "9.2(2)" }, { "version_affected": "=", "version_value": "7.0(3)F3(4)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8b)" }, { "version_affected": "=", "version_value": "6.0(2)A8(3)" }, { "version_affected": "=", "version_value": "7.0(3)I4(6t)" }, { "version_affected": "=", "version_value": "7.0(3)I5(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(8)" }, { "version_affected": "=", "version_value": "7.0(3)I7(5)" }, { "version_affected": "=", "version_value": "7.0(3)F3(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A8(4)" }, { "version_affected": "=", "version_value": "6.0(2)A6(3a)" }, { "version_affected": "=", "version_value": "6.0(2)A6(5a)" }, { "version_affected": "=", "version_value": "7.0(3)F2(1)" }, { "version_affected": "=", "version_value": "7.0(3)I4(8a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(9)" }, { "version_affected": "=", "version_value": "7.0(3)F3(2)" }, { "version_affected": "=", "version_value": "6.0(2)U6(2a)" }, { "version_affected": "=", "version_value": "7.0(3)I4(4)" }, { "version_affected": "=", "version_value": "6.0(2)U6(3)" }, { "version_affected": "=", "version_value": "7.0(3)I7(1)" }, { "version_affected": "=", "version_value": "7.0(3)F2(2)" }, { "version_affected": "=", "version_value": "7.0(3)IA7(2)" }, { "version_affected": "=", "version_value": "7.0(3)IA7(1)" }, { "version_affected": "=", "version_value": "6.0(2)A8(7b)" }, { "version_affected": "=", "version_value": "7.0(3)F1(1)" }, { "version_affected": "=", "version_value": "6.0(2)A6(1a)" }, { "version_affected": "=", "version_value": "6.0(2)A6(2)" }, { "version_affected": "=", "version_value": "6.0(2)A8(4a)" }, { "version_affected": "=", "version_value": "6.0(2)U6(4)" }, { "version_affected": "=", "version_value": "9.3(3)" }, { "version_affected": "=", "version_value": "7.0(3)I7(8)" }, { "version_affected": "=", "version_value": "6.0(2)U6(10a)" }, { "version_affected": "=", "version_value": "9.3(4)" }, { "version_affected": "=", "version_value": "9.3(5)" }, { "version_affected": "=", "version_value": "7.0(3)I7(9)" }, { "version_affected": "=", "version_value": "9.3(6)" }, { "version_affected": "=", "version_value": "10.1(2)" }, { "version_affected": "=", "version_value": "10.1(1)" }, { "version_affected": "=", "version_value": "9.3(5w)" }, { "version_affected": "=", "version_value": "9.3(7)" }, { "version_affected": "=", "version_value": "9.3(7k)" }, { "version_affected": "=", "version_value": "7.0(3)I7(9w)" }, { "version_affected": "=", "version_value": "10.2(1)" }, { "version_affected": "=", "version_value": "9.3(7a)" }, { "version_affected": "=", "version_value": "9.3(8)" }, { "version_affected": "=", "version_value": "7.0(3)I7(10)" }, { "version_affected": "=", "version_value": "10.2(1q)" }, { "version_affected": "=", "version_value": "10.2(2)" }, { "version_affected": "=", "version_value": "9.3(9)" }, { "version_affected": "=", "version_value": "10.1(2t)" }, { "version_affected": "=", "version_value": "10.2(3)" }, { "version_affected": "=", "version_value": "10.2(3t)" }, { "version_affected": "=", "version_value": "9.3(10)" }, { "version_affected": "=", "version_value": "10.2(2a)" }, { "version_affected": "=", "version_value": "10.3(1)" }, { "version_affected": "=", "version_value": "10.2(4)" }, { "version_affected": "=", "version_value": "10.3(2)" }, { "version_affected": "=", "version_value": "9.3(11)" }, { "version_affected": "=", "version_value": "10.3(3)" }, { "version_affected": "=", "version_value": "10.2(5)" }, { "version_affected": "=", "version_value": "9.3(12)" }, { "version_affected": "=", "version_value": "10.2(3v)" }, { "version_affected": "=", "version_value": "10.4(1)" }, { "version_affected": "=", "version_value": "10.3(99w)" }, { "version_affected": "=", "version_value": "10.2(6)" }, { "version_affected": "=", "version_value": "10.3(3w)" }, { "version_affected": "=", "version_value": "10.3(99x)" }, { "version_affected": "=", "version_value": "10.3(3o)" }, { "version_affected": "=", "version_value": "10.3(4)" }, { "version_affected": "=", "version_value": "10.3(3p)" }, { "version_affected": "=", "version_value": "10.3(4a)" }, { "version_affected": "=", "version_value": "10.4(2)" }, { "version_affected": "=", "version_value": "10.3(3q)" }, { "version_affected": "=", "version_value": "9.3(13)" }, { "version_affected": "=", "version_value": "10.3(5)" }, { "version_affected": "=", "version_value": "10.2(7)" }, { "version_affected": "=", "version_value": "10.4(3)" }, { "version_affected": "=", "version_value": "10.3(3x)" }, { "version_affected": "=", "version_value": "10.3(4g)" }, { "version_affected": "=", "version_value": "10.3(3r)" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-bshacepe-bApeHSx7", "refsource": "MISC", "name": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-bshacepe-bApeHSx7" } ] }, "source": { "advisory": "cisco-sa-nxos-bshacepe-bApeHSx7", "discovery": "INTERNAL", "defects": [ "CSCwh77783" ] }, "exploit": [ { "lang": "en", "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory." } ], "impact": { "cvss": [ { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } ] } }