Cisco NX-OS Software Call Home Command Injection (cisco-sa-callhome-cmdinj-zkxzSCY)

high Nessus Plugin ID 140202

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco NX-OS Software is affected by a command injection vulnerability due to insufficient input validation of specific Call Home configuration parameters when configured for transport method HTTP. An authenticated, remote attacker could modify parameters within the Call Home configuration in order to execute arbitrary commands with root privileges on the underlying OS. Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCve15011, CSCvg11715, CSCvg11732, CSCvg11752, CSCvh85161

See Also

http://www.nessus.org/u?651817a0

http://tools.cisco.com/security/center/viewErp.x?alertId=ERP-74239

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve15011

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg11715

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg11732

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg11752

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvh85161

Plugin Details

Severity: High

ID: 140202

File Name: cisco-sa-callhome-cmdinj-zkxzSCY.nasl

Version: 1.7

Type: combined

Family: CISCO

Published: 9/3/2020

Updated: 3/8/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2020-3454

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:nx-os

Required KB Items: Host/Cisco/NX-OS/Version, Host/Cisco/NX-OS/Model, Host/Cisco/NX-OS/Device

Exploit Ease: No known exploits are available

Patch Publication Date: 8/26/2020

Vulnerability Publication Date: 8/26/2020

Reference Information

CVE: CVE-2020-3454

CWE: 20

CISCO-SA: cisco-sa-callhome-cmdinj-zkxzSCY

IAVA: 2020-A-0394-S

CISCO-BUG-ID: CSCve15011, CSCvg11715, CSCvg11732, CSCvg11752, CSCvh85161