02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: ciscoCisco NX-OS Software Command Injection Vulnerability
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.49% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 39.7% of scored records. A rank, not a probability.
- NVD base score
- 5.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
- NVD analysis status
- Deferred. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2025-02-26 16:12Z1 YR AGO
- Last updated
- 2025-02-27 15:18Z1 YR AGO
- Reserved
- 2024-10-10
- Assigning CNA
- cisco
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 5.1)
- CNA CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
- Weaknesses
- CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Base
- Data version
- 5.1
- Document digest
- 0974e8da8bf343f851a9307b733a3d041d30f6cafeca04b313f49bdc1a211239
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
CiscoCisco NX-OS Software9.2(3), 7.0(3)I5(2), 6.0(2)A8(7a), 7.0(3)I4(5), 7.0(3)I4(6), 7.0(3)I4(3), 9.2(2v), 7.0(3)I4(7), 7.0(3)I4(1), 7.0(3)I4(8), 7.0(3)I4(2), 6.0(2)A8(11), 9.2(1), 9.2(2t), 9.2(3y), 7.0(3)I4(1t), 7.0(3)I7(6z), 9.3(2), 7.0(3)F3(3), 7.0(3)I7(3z), 7.0(3)IM7(2), 6.0(2)A8(11b), 7.0(3)I7(5a), 7.0(3)I6(1), 7.0(3)I5(3b), 9.2(4), 6.0(2)A8(10), 6.0(2)A8(2), 7.0(3)IC4(4), 7.0(3)F3(3c), 7.0(3)F3(1), 7.0(3)F3(5), 7.0(3)I7(2), 7.0(3)I5(3), 7.0(3)I7(3), 6.0(2)A8(6), 7.0(3)I6(2), 6.0(2)A8(5), 9.3(1), 6.0(2)A8(7), 7.0(3)I7(6), 6.0(2)A8(11a), 7.0(3)I4(8z), 7.0(3)I4(9), 7.0(3)I7(4), 7.0(3)I7(7), 6.0(2)A8(9), 6.0(2)A8(1), 6.0(2)A8(10a), 7.0(3)I5(1), 9.3(1z), 9.2(2), 7.0(3)F3(4), 7.0(3)I4(8b), 6.0(2)A8(3), 7.0(3)I4(6t), 7.0(3)I5(3a), 6.0(2)A8(8), 7.0(3)I7(5), 7.0(3)F3(3a), 6.0(2)A8(4), 7.0(3)I4(8a), 7.0(3)F3(2), 7.0(3)I4(4), 7.0(3)I7(1), 7.0(3)IA7(2), 7.0(3)IA7(1), 6.0(2)A8(7b), 6.0(2)A8(4a), 9.3(3), 7.0(3)I7(8), 9.3(4), 9.3(5), 7.0(3)I7(9), 9.3(6), 10.1(2), 10.1(1), 9.3(5w), 9.3(7), 9.3(7k), 7.0(3)I7(9w), 10.2(1), 9.3(7a), 9.3(8), 7.0(3)I7(10), 10.2(1q), 10.2(2), 9.3(9), 10.1(2t), 10.2(3), 10.2(3t), 9.3(10), 10.2(2a), 10.3(1), 10.2(4), 10.3(2), 9.3(11), 10.3(3), 10.2(5), 9.3(12), 10.2(3v), 10.4(1), 10.3(99w), 10.2(6), 10.3(3w), 10.3(99x), 10.3(3o), 10.3(4), 10.3(3p), 10.3(4a), 10.4(2), 10.3(3q), 9.3(13), 10.3(5), 10.2(7), 10.4(3), 10.3(3x), 10.3(4g), 10.5(1), 10.2(8), 10.3(3r), 10.3(6), 9.3(14), 10.3(4h)—