Vulnerabilities > Cisco > NX OS > 8.3.0.spg.0.30

DATE CVE VULNERABILITY TITLE RISK
2019-05-15 CVE-2019-1767 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection.
local
low complexity
cisco CWE-78
7.2
2019-05-15 CVE-2019-1735 Argument Injection or Modification vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device.
local
low complexity
cisco CWE-88
7.2
2019-05-15 CVE-2019-1727 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level.
local
low complexity
cisco CWE-78
7.2
2019-05-13 CVE-2019-1649 Improper Locking vulnerability in Cisco products
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component.
local
low complexity
cisco CWE-667
6.7
2019-03-11 CVE-2019-1616 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
5.0
2019-03-07 CVE-2019-1600 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system.
local
low complexity
cisco CWE-732
4.4
2019-03-06 CVE-2019-1594 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2019-03-06 CVE-2019-1588 Improper Privilege Management vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device.
local
low complexity
cisco CWE-269
2.1
2018-06-21 CVE-2018-0337 Incorrect Authorization vulnerability in Cisco Nx-Os
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device.
local
low complexity
cisco CWE-863
7.2