Skip to content
All vulnerabilities
CVE-2024-20399KEV

Cisco NX-OS Software CLI Command Injection Vulnerability

Severity
Medium6.7CVSS 3.1, Medium
EPSS
4%
Published
1 Jul 2024
Updated
17 Jun 2026

Description

Title, description and vendor guidance are quoted from the source records.

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode

Weakness: CWE-78

Known exploited

Added to CISA KEV on 2 Jul 2024

Federal remediation due date: 23 Jul 2024

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Exploit prediction

4% probability of exploitation in the next 30 days (percentile 91%).

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

Patcharo shows this vulnerability for information but does not match versions for this product yet.

  • Cisco Cisco NX-OS Software · 8.2(5), 7.3(6)N1(1a), 7.3(5)D1(1), 8.4(2), 7.3(6)N1(1), 6.2(2), 8.4(3), 9.2(3), 7.0(3)I5(2), 8.2(1), 6.0(2)A8(7a), 7.0(3)I4(5) and 306 more

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Cisco (CVE record)
Cisco (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC