CVE-2024-20397
Cisco NX-OS Software Image Verification Bypass Vulnerability
Severity
Medium 5.2
CVSS 3.1
Exploited
Not listed
EPSS
0.003
22.7th percentile
Discovered by
Third party
Published by the vendor
Published
Dec 4, 2024
Assigned by cisco
Description
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification. This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco NX-OS Software | Routing & Switching | cna-assigner |
| Cisco | Cisco Unified Computing System (UCS) | Other Products | cna-assigner |
Vendor-reported affected versions (3)
- Cisco · Cisco NX-OS Software
- Cisco · Cisco NX-OS System Software in ACI Mode
- Cisco · Cisco Unified Computing System (Managed)