Cisco NX-OS Software CLI Command Injection Vulnerability
- Severity
- Medium6.7CVSS 3.1, Medium
- EPSS
- 4%
- Published
- 1 Jul 2024
- Updated
- 17 Jun 2026
Description
Title, description and vendor guidance are quoted from the source records.
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode
Weakness: CWE-78
Known exploited
Added to CISA KEV on 2 Jul 2024
Federal remediation due date: 23 Jul 2024
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit prediction
4% probability of exploitation in the next 30 days (percentile 91%).
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Patcharo shows this vulnerability for information but does not match versions for this product yet.
- Cisco Cisco NX-OS Software · 8.2(5), 7.3(6)N1(1a), 7.3(5)D1(1), 8.4(2), 7.3(6)N1(1), 6.2(2), 8.4(3), 9.2(3), 7.0(3)I5(2), 8.2(1), 6.0(2)A8(7a), 7.0(3)I4(5) and 306 more
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Cisco (CVE record)
- Cisco (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC