| Vulnerability Name: | CVE-2013-1191 (CCN-93311) | ||||||||
| Assigned: | 2013-01-11 | ||||||||
| Published: | 2014-05-21 | ||||||||
| Updated: | 2014-05-27 | ||||||||
| Summary: | Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400. | ||||||||
| CVSS v3 Severity: | 8.0 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-1191 Source: CCN Type: cisco-sa-20140521-nxos Multiple Vulnerabilities in Cisco NX-OS-Based Products Source: CISCO Type: Vendor Advisory 20140521 Multiple Vulnerabilities in Cisco NX-OS-Based Products Source: CCN Type: BID-67574 Cisco NX-OS Virtual Device Context SSH Key CVE-2013-1191 Remote Privilege Escalation Vulnerability Source: XF Type: UNKNOWN cisco-nxos-cve20131191-priv-esc(93311) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||