CVE-2019-1727 is a privilege escalation vulnerability in the Python scripting subsystem of Cisco NX-OS Software. An authenticated, local attacker with administrative or Python execution privileges can exploit insufficient sanitization of user-supplied parameters to escape the Python sandbox and execute arbitrary commands, elevating their privilege level. This vulnerability has a CVSS score of 6.7 (Medium) due to its local attack vector and high impact on confidentiality, integrity, and availability, though it requires high privileges to exploit. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, suggesting a low current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.2, < 8.1\(1b\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 8.2, < 8.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\)i4, < 7.0\(3\)i4\(8\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.0\(3\)i5, < 7.0\(3\)i7\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.3, < 7.3\(4\)n1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.