CVE-2019-14905

MEDIUM

Ansible Engine < 2.7.16 - OS Command Injection via nxos_file_copy Module

Title source: llm
STIX 2.1

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

References (6)

Core 6
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14905
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2020:0218
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2020:0216
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00021.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00026.html

Scores

CVSS v3 5.6
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-668 CWE-20 CWE-73
Status published
Products (9)
fedoraproject/fedora 30
opensuse/backports_sle 15.0 sp1
opensuse/leap 15.1
pypi/ansible 2.7.0a1 - 2.7.16PyPI
redhat/ansible_engine 2.7.0 - 2.7.16
redhat/ansible_tower 3.0.0
redhat/ceph_storage 3.0
redhat/cloudforms_management_engine 5.0
redhat/openstack 13
Published Mar 31, 2020
Tracked Since Feb 18, 2026