CVE-2018-0306 describes a command-injection vulnerability in the CLI parser of Cisco NX-OS Software, affecting numerous Nexus and MDS 9000 Series switches. An authenticated, local attacker can exploit insufficient input validation to inject malicious commands. This high-severity vulnerability (CVSS 7.8) allows an attacker to execute arbitrary commands with root privileges, requiring only a feature license to be uploaded. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it's not in CISA's KEV catalog, it has received some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.3\(3\)n1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
8.1\(0.2\)s0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1\(0.2\)s0:*:*:*:*:*:*:* | ||
8.1\(0\)bd\(0.20\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1\(0\)bd\(0.20\):*:*:*:*:*:*:* | ||
8.1\(0.59\)s0CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1\(0.59\)s0:*:*:*:*:*:*:* | ||
8.1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:8.1\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.