Cisco Announced Four Vulnerabilities In Its Fxos And Nx Os Network Operating Systems Cybers Guards
CVE-2022-20650, a command injection flaw that may be exploited remotely without authentication to execute arbitrary commands as root, is the most serious of the security weaknesses, with a CVSS score of 8.8. The flaw arises because user-supplied data isn’t properly checked, allowing an attacker to execute instructions on the operating system by sending a forged HTTP POST request to the NX-API function on the affected device. Cisco points out that the NX-API feature is turned off by default....