CVE-2013-1191
Last modified
CVE-2013-1191 is a vulnerability of currently unknown severity. Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 6.1 |
| Cisco | Nx-Os | 6.1\(1\) |
| Cisco | Nx-Os | 6.1\(2\) |
| Cisco | Nx-Os | 6.1\(3\) |
| Cisco | Nx-Os | 6.1\(4\) |
| Cisco | Nx-Os | 6.1\(4a\) |
| Cisco | Nexus 7000 | All versions |
| Cisco | Nexus 7000 10-Slot | All versions |
| Cisco | Nexus 7000 18-Slot | All versions |
| Cisco | Nexus 7000 9-Slot | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1191?
How severe is CVE-2013-1191?
How do I fix CVE-2013-1191?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1185The web interface in the Manager component in Cisco Unified …
- CVE-2013-1186Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2…
- CVE-2013-1187The Connection Manager in Cisco Jabber Extensible Communicat…
- CVE-2013-1188Cisco Unified Communications Manager (CUCM) does not properl…
- CVE-2013-1189Cisco Universal Broadband (aka uBR) 10000 series routers, wh…
- CVE-2013-1190The C-Series Rack Server component 1.4 in Cisco Unified Comp…
- CVE-2013-1192The JAR files on Cisco Device Manager for Cisco MDS 9000 dev…
- CVE-2013-1193The Secure Shell (SSH) implementation on Cisco Adaptive Secu…
- CVE-2013-1194The ISAKMP implementation on Cisco Adaptive Security Applian…
- CVE-2013-1195The time-based ACL implementation on Cisco Adaptive Security…
- CVE-2013-1196The command-line interface in Cisco Secure Access Control Sy…
- CVE-2013-1197The XML parser in the server in Cisco Unified Presence (CUP)…
Are you affected by CVE-2013-1191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
