[{"@context":"https:\/\/schema.org\/","@type":"BlogPosting","@id":"https:\/\/techloot.co.uk\/security\/cisco-nx-os-zero-day-command-injection-vulnerability-under-active-exploitation\/#BlogPosting","mainEntityOfPage":"https:\/\/techloot.co.uk\/security\/cisco-nx-os-zero-day-command-injection-vulnerability-under-active-exploitation\/","headline":"Cisco NX-OS Zero-Day Command Injection Vulnerability Under Active Exploitation","name":"Cisco NX-OS Zero-Day Command Injection Vulnerability Under Active Exploitation","description":"A severe vulnerability in the Command Line Interface (CLI) of Cisco NX-OS Software is currently being actively exploited, enabling attackers to execute arbitrary commands as root on compromised devices. This zero-day flaw, identified as CVE-2024-20399, poses a significant risk to network security, particularly for organizations using Cisco\u2019s Nexus and MDS series switches. The vulnerability stems&hellip;","datePublished":"2024-07-02","dateModified":"2024-07-18","author":{"@type":"Person","@id":"https:\/\/techloot.co.uk\/author\/andre\/#Person","name":"Andrej Kovacevic","url":"https:\/\/techloot.co.uk\/author\/andre\/","image":{"@type":"ImageObject","@id":"https:\/\/techloot.co.uk\/wp-content\/uploads\/2017\/06\/techloot-editor-150x150.jpg","url":"https:\/\/techloot.co.uk\/wp-content\/uploads\/2017\/06\/techloot-editor-150x150.jpg","height":96,"width":96}},"publisher":{"@type":"Organization","name":"Tech Loot","logo":{"@type":"ImageObject","@id":"https:\/\/techlootio.wpengine.com\/wp-content\/uploads\/2018\/09\/techloot-footer-logo.png","url":"https:\/\/techlootio.wpengine.com\/wp-content\/uploads\/2018\/09\/techloot-footer-logo.png","width":600,"height":60}},"image":{"@type":"ImageObject","@id":"https:\/\/techloot.co.uk\/wp-content\/uploads\/2024\/07\/Screenshot_790.jpg","url":"https:\/\/techloot.co.uk\/wp-content\/uploads\/2024\/07\/Screenshot_790.jpg","height":894,"width":1589},"url":"https:\/\/techloot.co.uk\/security\/cisco-nx-os-zero-day-command-injection-vulnerability-under-active-exploitation\/","about":["Security"],"wordCount":403,"keywords":["#Cisco","#CynetXDR","#ITSecurity","#NetworkSecurity","#technews","#ZeroDay","Cybersecurity"],"articleBody":"A severe vulnerability in the Command Line Interface (CLI) of Cisco NX-OS Software is currently being actively exploited, enabling attackers to execute arbitrary commands as root on compromised devices.This zero-day flaw, identified as CVE-2024-20399, poses a significant risk to network security, particularly for organizations using Cisco\u2019s Nexus and MDS series switches.The vulnerability stems from inadequate validation of arguments passed to specific configuration CLI commands.&#8220;Is Your System Under Attack? Try Cynet XDR: Automated Detection &amp; Response for Endpoints, Networks, &amp; Users!&#8221; &#8211; Free DemoAn authenticated local attacker with administrator credentials can exploit this flaw by providing crafted input as an argument for an affected configuration CLI command.Successful exploitation grants the attacker root privileges on the underlying operating system, enabling the execution of arbitrary commands.Affected ProductsThe following Cisco products are vulnerable if they are running a susceptible release of Cisco NX-OS Software:MDS 9000 Series Multilayer SwitchesNexus 3000 Series SwitchesNexus 5500 Platform SwitchesNexus 5600 Platform SwitchesNexus 6000 Series SwitchesNexus 7000 Series SwitchesNexus 9000 Series Switches in standalone NX-OS modeNotably, certain models within the Nexus 3000 and Nexus 9000 series are not affected if they are running Cisco NX-OS Software releases 9.3(5) and later, with specific exceptions like the N3K-C3264C-E and N9K-C92348GC-X models, which require further updates to versions 10.4.3 and later.Exploitation and MitigationThe Cisco Product Security Incident Response Team (PSIRT) became aware of this vulnerability\u2019s active exploitation in April 2024. Cybersecurity firm Sygnia attributed these attacks to a Chinese state-sponsored threat actor, Velvet Ant, who leveraged the flaw to deploy custom malware on compromised devices.This malware allows remote connection, file upload, and malicious code execution without triggering system syslog messages, thereby concealing the attack.Cisco has released software updates to address this vulnerability. However, there are no workarounds available.Administrators are urged to apply the updates promptly and regularly monitor and change the credentials for administrative users, such as network-admin and vdc-admin, to mitigate potential risks.Cisco provides the Cisco Software Checker tool to determine exposure and find the appropriate software updates. This tool identifies impacted software releases and the earliest fixed versions. Administrators can access this tool on the Cisco Software Checker page.Organizations using affected Cisco products should prioritize applying the necessary patches and continuously monitor their network for any signs of compromise.Are you from SOC\/DFIR Teams? &#8211; Sign up for a free ANY.RUN account to Analyze Advanced Malware Files"},{"@context":"https:\/\/schema.org\/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Security","item":"https:\/\/techloot.co.uk\/security\/#breadcrumbitem"},{"@type":"ListItem","position":2,"name":"Cisco NX-OS Zero-Day Command Injection Vulnerability Under Active Exploitation","item":"https:\/\/techloot.co.uk\/security\/cisco-nx-os-zero-day-command-injection-vulnerability-under-active-exploitation\/#breadcrumbitem"}]}]