Zero-day vulnerability in Cisco NX-OS

OS Command Injection
CVE-2024-20399

Not patched

Vulnerability details

Advisory: SB2024070156 - Privilege escalation in Cisco NX-OS Software

Vulnerable component: Cisco NX-OS

CVE-ID: CVE-2024-20399

CVSSv3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Description:

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper input validation. A local user can execute arbitrary commands as root on the underlying operating system of an affected device.

Note, the vulnerability is being actively exploited in the wild since of April 2024.