6.8
CVSSv2

CVE-2013-5556

Published: 18/11/2013 Updated: 20/11/2013
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 605
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and previous versions for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nexus 1000v 4.2\\(1\\)vsg1\\(1\\)

cisco nexus 1000v 5.2\\(1\\)sm1\\(5.1\\)

cisco nexus 1000v 4.2\\(1\\)sv1\\(5.1a\\)

cisco nexus 1000v 4.2\\(1\\)sv1\\(5.1\\)

cisco nexus 1000v 4.2\\(1\\)_sv1\\(4b\\)

cisco nexus 1000v 4.2\\(1\\)_sv1\\(4a\\)

cisco nexus 1000v

cisco nexus 1000v 4.2\\(1\\)sv1\\(5.2\\)

cisco nexus 1000v 4.2\\(1\\)_sv1\\(4\\)

Vendor Advisories

A vulnerability in the license installation module of the Cisco Nexus 1000V could allow an authenticated, local attacker to execute arbitrary shell commands The vulnerability is due to a failure of the install all iso command to properly validate user-supplied input An attacker could exploit this vulnerability by providing crafted arguments to t ...