LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-20399: Cisco NX-OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 2, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 23, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-20399 to its Known Exploited Vulnerabilities catalog on Jul 2, 2024, with a federal patch deadline of Jul 23, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating…

CVE-2024-20399 is a command injection vulnerability in the command line interface (CLI) of Cisco NX-OS. An authenticated local attacker who can reach the CLI may execute arbitrary commands as root on the underlying operating system of an affected device. Because NX-OS commonly runs on core network switches and fabric devices, successful abuse can give an attacker full control of the platform and a foothold for further lateral movement or traffic interception. Exact affected releases and configurations must be confirmed against the vendor advisory.

How it works

The flaw is classified as CWE-78 (OS Command Injection). In products of this class, user-supplied input that reaches a shell or system call is not sufficiently sanitized. On Cisco NX-OS the injection surface is the CLI itself. An attacker who already possesses valid local credentials can craft CLI input that causes the device to execute additional operating-system commands with root privileges. No remote unauthenticated path is described; the attacker must first obtain authenticated local access. Public detail beyond the CISA summary is limited, so defenders should treat any CLI session that can reach the vulnerable code path as potentially dangerous until the vendor patch is applied.

Am I affected? How to find it in your systems

Cisco NX-OS is the operating system used on many Cisco Nexus data-center switches, some MDS storage switches, and selected other Cisco networking platforms. Inventory every device that reports NX-OS as its OS. Typical discovery methods include:

Compare the collected version strings against the fixed releases listed in the Cisco advisory for CVE-2024-20399. Also note any devices that allow local CLI access via console, SSH, or other management channels; those are the ones that expose the attack surface. Telemetry or logging signs of exploitation are not specifically documented, but look for unexpected CLI command sequences, sudden privilege escalations, or new processes running as root that do not match normal administrative activity. Confirm all version and configuration details against the official vendor advisory before declaring a device safe.

How to remediate

The primary remediation is to apply the software update published by Cisco for the affected NX-OS releases. Follow the vendor’s installation and verification procedures exactly; reboot or reload requirements, if any, will be stated in the advisory. After patching, re-inventory the devices to confirm the new version is running. For this class of vulnerability, additional hardening steps reduce residual risk:

If the vendor provides additional mitigations or configuration work-arounds, implement those as well. CISA’s required action is to apply the vendor mitigations or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls that limit who can reach the CLI and what they can do:

These measures do not eliminate the vulnerability; they only shrink the window of opportunity until the vendor patch is applied.

If your data may have been exposed

Actively exploited command-injection flaws on network infrastructure can lead to full device compromise and subsequent data exposure or lateral movement. Ransomware use of this specific CVE is not documented. If you suspect an affected device was abused, treat the incident as a potential breach: isolate the device, preserve logs, and begin forensic review. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether any related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · NX-OS
WeaknessCWE-78
Added to CISA KEVJul 2, 2024
Federal patch deadlineJul 23, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities