CVE-2024-20289

Cisco NX-OS Software Command Injection Vulnerability

Severity
Medium 4.4
CVSS 3.1
Exploited
Not listed
EPSS
0.002
13.5th percentile
Discovered by
Vendor
Published by the vendor
Published
Aug 28, 2024
Assigned by cisco

Description

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of arguments for a specific CLI command. An attacker could exploit this vulnerability by including crafted input as the argument of the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the currently logged-in user.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Cisco Cisco NX-OS Software Routing & Switching cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco NX-OS Software
  • Cisco · Cisco NX-OS System Software in ACI Mode