PT-2024-4435 · Cisco · Cisco Nx-Os+1
Published
2024-07-01
·
Updated
2026-06-13
·
CVE-2024-20399
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS Software versions prior to the fixed version
Description
A vulnerability in the Command Line Interface (CLI) of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. The vulnerability has been exploited by the China-linked threat group Velvet Ant to gain control and evade detection.
Recommendations
To resolve the issue, apply the software updates released by Cisco that address this vulnerability. There are no workarounds that address this vulnerability. Restrict administrative access and use central authentication, authorization, and accounting management for users (AAA). Regularly change administrator credentials and check devices for signs of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Nx-Os
Cisco Nexus