CVE ID
CVE-2024-20399
Vulnerability Name
Cisco NX-OS Command Injection Vulnerability
- Project: Cisco
- Product: NX-OS
Date
- Date Added: 2024-07-02
- Due Date: 2024-07-23
Description
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-cmd-injection-xD9OhyOP; https://nvd.nist.gov/vuln/detail/CVE-2024-20399
Related Security News
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
- Cisco bug lets hackers run commands as root on UWRB access points
- Cisco warns of backdoor admin account in Smart Licensing Utility
- Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System Control
- Exploit released for Cisco SSM bug allowing admin password changes
- Cisco SSM On-Prem bug lets hackers change any user's password
- CISA urges devs to weed out OS command injection vulnerabilities
- Chinese Hackers Exploiting Cisco Switches Zero-Day to Deliver Malware
- Cisco warns of NX-OS zero-day exploited to deploy custom malware
Top comments (0)