Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20907

Опубликовано: 22 июл. 2022
Источник: nvd
CVSS3: 6
CVSS3: 6.7
EPSS Низкий

Описание

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by authenticating as the rescue-user and executing vulnerable CLI commands using a malicious payload. A successful exploit could allow the attacker to elevate privileges to root on an affected device.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:nexus_dashboard:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 2.2\(1e\) (исключая)

EPSS

Процентиль: 5%
0.00022
Низкий

6 Medium

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-367
CWE-269

Связанные уязвимости

CVSS3: 6.7
github
больше 3 лет назад

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by authenticating as the rescue-user and executing vulnerable CLI commands using a malicious payload. A successful exploit could allow the attacker to elevate privileges to root on an affected device.

CVSS3: 6.7
fstec
больше 3 лет назад

Уязвимость интерфейса командной строки (CLI) платформы аналитики и автоматизации работы с многооблачными сетями дата-центров Cisco Nexus Dashboard, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 5%
0.00022
Низкий

6 Medium

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-367
CWE-269