Command injection in Cisco NX-OS - CVE-2018-0306
Published: June 20, 2018 / Updated: June 25, 2018
Cisco NX-OS
Detailed vulnerability description
The vulnerability allows a local attacker to execute arbitrary commands on the target system.
The vulnerability exists in the CLI parser of Cisco NX-OS Software due to insufficient input validation of command arguments. A local attacker can inject malicious command arguments into a vulnerable CLI command and execute arbitrary commands with root privileges.