Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
Unauthenticated attackers can gain root code execution on Cisco NX-OS through crafted NX-API HTTP requests.
A vulnerability in the NX-API feature of Cisco NX-OS Software could let an unauthenticated remote attacker execute arbitrary code with root privileges or cause a denial of service. The flaw is insufficient validation of data sent to the NX-API, and exploitation uses a crafted HTTP request. A successful attack can crash processes and reload the device. Cisco has released software updates.
- Insufficient NX-API input validation enables unauthenticated remote code execution.
- Successful exploitation runs arbitrary code as root or reloads the device.
- A crafted HTTP request to the NX-API triggers the flaw.
- Cisco has released software updates.
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition. Cisco has released software updates that address this vulnerability.…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.