Skip to content
COOEY

EXPOSURES › CVE-2024-20399

CVE-2024-20399

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-20399 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildunpatched

Cisco NX-OS CLI allows authenticated local attackers to execute root commands via command injection.

An authenticated local attacker can execute arbitrary root commands on affected Cisco NX-OS devices, enabling full system compromise. DIB orgs must ensure NX-OS is patched and restrict CLI access to prevent privilege escalation and lateral movement.

Shame score — A known command injection vulnerability in a widely deployed enterprise OS that allows local root execution, though not zero-day or ransomware-linked.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized