Wednesday, 09 July 2025

Cisco fixed 0-day vulnerability in NX-OS

Cisco has patched a zero-day command injection vulnerability in NX-OS. The vulnerability is tracked as CVE-2024-20399 (CVSS score 6.0) and affects the NX-OS command line interface, allowing a local attacker to execute arbitrary commands with root privileges.

CVE-2024-20399 affects Cisco MDS 9000, Nexus 3000, Nexus 5500, Nexus 5600, Nexus 6000, Nexus 7000, and Nexus 9000 series switches. Updated firmware versions are currently available for all devices.

More information on vulnerability and updates is available in Cisco security advisory - cisco.com.

09 July 2024

-
62