PT-2024-4435 · Cisco · Cisco Nx-Os+1

Published

2024-07-01

·

Updated

2026-06-13

·

CVE-2024-20399

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software versions prior to the fixed version
Description A vulnerability in the Command Line Interface (CLI) of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. The vulnerability has been exploited by the China-linked threat group Velvet Ant to gain control and evade detection.
Recommendations To resolve the issue, apply the software updates released by Cisco that address this vulnerability. There are no workarounds that address this vulnerability. Restrict administrative access and use central authentication, authorization, and accounting management for users (AAA). Regularly change administrator credentials and check devices for signs of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04937
CVE-2024-20399

Affected Products

Cisco Nx-Os
Cisco Nexus