CVE-2019-14905

unknown
Published 2021-04-20 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
CVSS v2
VIR risk

Description

A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2019-14905.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-14905

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed2.9.4+dfsg-1
debian debianforkyfixed2.9.4+dfsg-1
debian debiansidfixed2.9.4+dfsg-1
debian debianbookwormfixed2.9.4+dfsg-1
debian debiantrixiefixed2.9.4+dfsg-1
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIansible>=2.7.0a1,<2.7.162.7.16
python PyPIansible>=2.8.0a1,<2.8.82.8.8
python PyPIansible>=2.9.0a1,<2.9.32.9.3
python PyPIansible>=2.9.0,<2.9.32.7.16

References

Verify integrity in audit chain (admin only). AS-IS.