CVE-2019-1591 is a high-severity vulnerability affecting Cisco Nexus 9000 Series ACI Mode Switches running software versions prior to 14.0(3d). This flaw allows an authenticated, local attacker to escape a restricted shell and execute arbitrary commands with root privileges due to insufficient input sanitization in a specific CLI command. The CVSS score of 7.8 indicates a high impact on confidentiality, integrity, and availability, with low attack complexity and no user interaction required. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in KEV, the vulnerability has received some community discussion and media coverage, though it is not considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.0\(3d\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.