Improper input validation in Cisco Systems, Inc products - CVE-2017-12340

 

Improper input validation in Cisco Systems, Inc products - CVE-2017-12340

Published: November 29, 2017 / Updated: December 1, 2017


Vulnerability identifier: #VU9516
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12340
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions on the target system.

The vulnerability exists due to insufficient sanitization of user-supplied parameters that are passed to certain functions of the Python scripting sandbox. A local attacker can escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the authenticated user.


Affected software

Multilayer Director Switches
Nexus 7700 Series Switches
Nexus 7000 Series Switches

How to mitigate CVE-2017-12340

Install update from vendor's website.


External References

Related Security Bulletins