PT-2024-18658 · Cisco · Cisco Nx-Os+5
Ferdinand Nölscher
·
Published
2024-12-04
·
Updated
2025-02-06
·
CVE-2024-20397
CVSS v2.0
5.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS Software (affected versions not specified)
Description
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification. This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software. The issue affects over 100 models, including MDS 9000, Nexus 3000/7000/9000.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus
Mds 9000
Nexus 3000
Nexus 7000
Nexus 9000