#VU13431 Command injection in Cisco NX-OS - CVE-2018-0313
Published: June 20, 2018 / Updated: June 25, 2018
Cisco NX-OS
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists in the NX-API feature of Cisco NX-OS Software due to incorrect input validation of user-supplied data to the NX-API subsystem. A remote attacker can send a malicious HTTP or HTTPS packet to the management interface of an affected system that has the NX-API feature enabled, inject and execute arbitrary commands with root privileges.