Database/Firmware, BMC & network fabric
Cisco NX-OS: Python sandbox escape gives a low-privilege user shell access to the switch OS
Impact
The NX-OS Python interpreter is meant to confine scripted automation to a sandbox. Insufficient input validation lets an authenticated low-privilege user manipulate interpreter functions and execute arbitrary commands on the underlying operating system with that user's privileges. On a fabric switch this converts a read-mostly or restricted-role account - the kind handed to automation, monitoring or junior operators - into general-purpose access on a device that carries every tenant's traffic. It is not a direct jump to root: commands run as the authenticated user, and the vendor scores confidentiality and integrity as low.
Who can reach it
A local, authenticated user with low privileges on the switch who can invoke the embedded Python interpreter. Authentication is required; no network-only path is described.
What to do
Upgrade to a fixed NX-OS release per Cisco advisory cisco-sa-nxos-mppe-dhKZAFgb, which reloads the switch and so needs a per-device maintenance window. In the meantime, treat the Python interpreter as a privileged feature: review which roles can reach it and prune low-privilege accounts that do not need it. The record does not state a vendor workaround or specific fixed versions - read the advisory for those.
References
Related entries
- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeCVE-2021-3956 · Lenovo XClarity Controller (LDAP mode)Medium
- tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATEDCVE-2024-29040 · tpm2-tss (FAPI quote verification)Medium
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMICVE-2024-8059 · Lenovo XClarity Controller (XCC) - audit logMedium
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userCVE-2025-31938 · Intel Xeon 6 Scalable processors with Intel TDX (subsystem access control)Medium
- Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashesCVE-2025-54548 · Arista DANZ Monitoring Fabric (debug API exposing the config database)Medium
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.