CVE-2024-20399 - Cisco NX-OS Command Injection Vulnerability
Project:Cisco
Product:NX-OS
Date Added:2024-07-02Due Date:2024-07-23
Vulnerability Name
Cisco NX-OS Command Injection Vulnerability
Description
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP
https://nvd.nist.gov/vuln/detail/CVE-2024-20399
Related News Articles
Cisco bug lets hackers run commands as root on UWRB access pointsNovember 7, 2024
Cisco warns of backdoor admin account in Smart Licensing UtilitySeptember 5, 2024
Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System ControlAugust 23, 2024
Exploit released for Cisco SSM bug allowing admin password changesAugust 9, 2024
Cisco SSM On-Prem bug lets hackers change any user's passwordJuly 18, 2024