A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
N9k-c9316d-gx
Subscribe
N9k-c9332d-gx2b
Subscribe
N9k-c9348d-gx2a
Subscribe
N9k-c93600cd-gx
Subscribe
N9k-c9364d-gx2a
Subscribe
Nexus 3048
Subscribe
Nexus 31108pc-v
Subscribe
Nexus 31108tc-v
Subscribe
Nexus 31128pq
Subscribe
Nexus 3132c-z
Subscribe
Nexus 3132q-v
Subscribe
Nexus 3132q-x
Subscribe
Nexus 3132q-xl
Subscribe
Nexus 3164q
Subscribe
Nexus 3172pq
Subscribe
Nexus 3172pq-xl
Subscribe
Nexus 3172tq-xl
Subscribe
Nexus 3232c
Subscribe
Nexus 3264c-e
Subscribe
Nexus 3264q
Subscribe
Nexus 3408-s
Subscribe
Nexus 34180yc
Subscribe
Nexus 3432d-s
Subscribe
Nexus 3464c
Subscribe
Nexus 3524-x
Subscribe
Nexus 3524-xl
Subscribe
Nexus 3548-x
Subscribe
Nexus 3548-xl
Subscribe
Nexus 36180yc-r
Subscribe
Nexus 3636c-r
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5672up
Subscribe
Nexus 5672up-16g
Subscribe
Nexus 6000
Subscribe
Nexus 6001
Subscribe
Nexus 6004
Subscribe
Nexus 92160yc-x
Subscribe
Nexus 92300yc
Subscribe
Nexus 92304qc
Subscribe
Nexus 92348gc-x
Subscribe
Nexus 9236c
Subscribe
Nexus 9272q
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93108tc-fx
Subscribe
Nexus 93108tc-fx3p
Subscribe
Nexus 93120tx
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 93180yc-fx
Subscribe
Nexus 93180yc-fx3
Subscribe
Nexus 93216tc-fx2
Subscribe
Nexus 93240yc-fx2
Subscribe
Nexus 9332c
Subscribe
Nexus 93360yc-fx2
Subscribe
Nexus 9336c-fx2
Subscribe
Nexus 9336c-fx2-e
Subscribe
Nexus 9348gc-fxp
Subscribe
Nexus 9364c
Subscribe
Nexus 9364c-gx
Subscribe
Nexus 9504 Switch
Subscribe
Nexus 9508 Switch
Subscribe
Nexus 9516 Switch
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25900 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-06T16:29:59.156Z
Reserved: 2021-11-02T00:00:00
Link: CVE-2022-20650
Updated: 2024-08-03T02:17:53.010Z
Status : Modified
Published: 2022-02-23T18:15:18.690
Modified: 2024-11-21T06:43:14.530
Link: CVE-2022-20650
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD