Junglewise Threat Intelligence

CVE-2024-20399: Cisco NX-OS Command Injection Vulnerability

CVE-2024-20399 · Severity: critical · CVSS 6.7 · Exploited in the wild · Published 2024-07-02

Vendors: Cisco.

Executive brief

A command injection vulnerability in the Cisco NX-OS CLI allows an authenticated attacker with Administrator credentials to execute arbitrary commands as root on the underlying operating system. The issue stems from insufficient validation of arguments passed to specific configuration CLI commands.

Affected products

  • Cisco NX-OS Software 6.2(2), 6.2(2a), 6.2(6), 6.2(6a) and others
  • Cisco Nexus 3000 Series Switches
  • Cisco Nexus 7000 Series Switches 8.1(1) and later
  • Cisco Nexus 9000 Series Switches

Timeline

  • 2024-07-02: disclosed
  • 2024-07-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-02: exploited: Reported as exploited in the wild by Sygnia and CISA