VYPR
Medium severity6.4NVD Advisory· Published May 15, 2019· Updated Jun 17, 2026

CVE-2019-1732

CVE-2019-1732

Description

A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to arbitrary command injection. The vulnerability is due to the lack of a proper locking mechanism on critical variables that need to stay static until used. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a set of RPM-related CLI commands. A successful exploit could allow the attacker to perform arbitrary command injection. The attacker would need administrator credentials for the targeted device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*range: >=7.0\(3\)i4,<7.0\(3\)i7\(4\)
    • cpe:2.3:o:cisco:nx_os:*:*:*:*:*:*:*:*range: >=7.0\(3\),<7.0\(3\)f3\(5\)
  • (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.