Lucene search

K
zdiPedro Ribeiro (@pedrib1337 | [email protected]) from Agile Information SecurityZDI-22-507
HistoryMar 11, 2022 - 12:00 a.m.

Cisco Nexus Dashboard Fabric Controller Improper Privilege Management Privilege Escalation Vulnerability

2022-03-1100:00:00
Pedro Ribeiro (@pedrib1337 | [email protected]) from Agile Information Security
www.zerodayinitiative.com
21

0.098 Low

EPSS

Percentile

94.9%

This vulnerability allows local attackers to escalate privileges on affected installations of Cisco Nexus Dashboard Fabric Controller. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of a user permission. A crafted tcpdump command can trigger execution of a privileged operation. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.