Database/Firmware, BMC & network fabric
Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated admin
CVSS 6.7CVE-2017-12334Firmware, BMC & network fabriccurated
Impact
CLI command injection giving root-level execution on the switch OS for an authenticated admin — the same pattern later re-appeared as the exploited CVE-2024-20399
Who can reach it
Network, authenticated admin
What to do
NX-OS upgrade with fabric failover; recurrence of the class means CLI-injection hardening on the switch OS is a standing item, not a one-off patch
References
Related entries
- Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI sessionCVE-2024-20399 · Cisco NX-OS CLIMedium
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformCVE-2018-12204 · Intel Server Board / Server System / Compute Module platform firmwareMedium
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareCVE-2019-0119 · Intel Xeon D / Xeon Scalable system firmware, Server Board and Server SystemMedium
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedCVE-2019-11157 · Intel SGX / dynamic voltage and frequency scaling interfaceMedium
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesCVE-2020-11488 · NVIDIA DGX BMC (AMI firmware)Medium
- GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carveCVE-2020-27779 · GRUB2 (cutmem command)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.