CVE-2017-6650 Details
Description
A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arguments into the Telnet CLI command. An exploit could allow the attacker to read or write arbitrary files at the user's privilege level outside of the user's path. Cisco Bug IDs: CSCvb86771.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-nss1 | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/98528 | CVE | Third Party AdvisoryVendor Advisory |
| http://www.securitytracker.com/id/1038518 | CVE | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170517-nss1 | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/98528 | [email protected] | Third Party AdvisoryVendor Advisory |
| http://www.securitytracker.com/id/1038518 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco nx-os | 7.1(1)n1(1) 7.1(2)n1(1) 7.1(3)n1(1) 7.1(3)n1(2) 7.1(3)n1(2.1) 7.1(3)n1(3.12) 7.1(4)n1(1) 7.2(0)d1(0.437) 7.2(0)n1(1) 7.2(0)zz(99.1) 7.2(1)n1(1) 7.3(0)n1(1) |
CPE
Remediation
| |
| cisco nexus 5548up | All versions |
CPE
Remediation
| |
| cisco nexus 5596t | All versions |
CPE
Remediation
| |
| cisco nexus 5596up | All versions |
CPE
Remediation
| |
| cisco nexus 56128p | All versions |
CPE
Remediation
| |
| cisco nexus 5624q | All versions |
CPE
Remediation
| |
| cisco nexus 5648q | All versions |
CPE
Remediation
| |
| cisco nexus 5672up | All versions |
CPE
Remediation
| |
| cisco nexus 5672up-16g | All versions |
CPE
Remediation
| |
| cisco nexus 5696q | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 18, 2017 | CVE Modified | [email protected] |
| Jul 8, 2017 | CVE Modified | [email protected] |
| May 31, 2017 | Initial Analysis | [email protected] |
| May 25, 2017 | CVE Modified | [email protected] |