CVE-2019-14905

Aliases:GHSA-frxj-5j27-f8rfPYSEC-2020-206
Modified
Published: 31 Mar 2020, 16:20
Last modified:05 Aug 2024, 00:34

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.3 HIGH
v3.0 (cve.org)
EPSS Score
0.27% LOW
0% probability +0.22%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

31 Mar 2020, 16:20
Published
Vulnerability first disclosed
05 Aug 2024, 00:34
Last Modified
Vulnerability information updated

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

CVSS Metrics

  • v4.0HIGHScore: 7CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
  • v3.0HIGHScore: 7.3CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.27% Percentile: 51%

Techniques & Countermeasures

  • CWE-668Exposure of Resource to Wrong Sphere

    The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-73External Control of File Name or Path

    The product allows user input to control or influence paths or file names that are used in filesystem operations.

Affected Systems

  • fedoraprojectfedora

    30

  • opensusebackports_sle

    15.0:sp1

  • opensuseleap

    15.1

  • PyPIansible

    ≥ 2.7.0a1, < 2.7.16 | ≥ 2.8.0a1, < 2.8.8 | ≥ 2.9.0a1, < 2.9.3 | ≥ 2.9.0, < 2.9.3

  • red hatansible

    2.9.x before 2.9.3 | 2.8.x before 2.8.8 | 2.7.x before 2.7.16 | 2.7.x and earlier

  • redhatansible_engine

    ≥ 2.7.0, < 2.7.16 | ≥ 2.8.0, < 2.8.8 | ≥ 2.9.0, < 2.9.3

  • redhatansible_tower

    3.0.0

  • redhatceph_storage

    3.0

  • redhatcloudforms_management_engine

    5.0

  • redhatopenstack

    13

References (12)