Lucene search

K
cvelistCiscoCVELIST:CVE-2024-20399
HistoryJul 01, 2024 - 4:11 p.m.

CVE-2024-20399

2024-07-0116:11:44
cisco
www.cve.org
9
cisco
nx-os
software
vulnerability
command execution
authentication
local attacker
root privileges
insufficient validation
crafted input
configuration cli
administrator credentials

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

0.023 Low

EPSS

Percentile

89.7%

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.

This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.

Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.

CNA Affected

[
  {
    "vendor": "Cisco",
    "product": "Cisco NX-OS Software",
    "versions": [
      {
        "version": "6.0(2)A6(1)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(1a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(2)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(2a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(3)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(3a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(4)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(4a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(5a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(5b)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(6)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(7)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A6(8)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(1)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(2)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(3)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(4)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(4a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(5)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(6)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(7)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(7a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(7b)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(8)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(9)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(10a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(10)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(11)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(11a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)A8(11b)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(1)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(2)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(3)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(4)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(5)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(6)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(7)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(8)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(1a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(2a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(3a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(4a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(5a)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(5b)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(5c)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(9)",
        "status": "affected"
      },
      {
        "version": "6.0(2)U6(10)",
        "status": "affected"
      },
      {
        "version": "6.2(2)",
        "status": "affected"
      },
      {
        "version": "6.2(2a)",
        "status": "affected"
      },
      {
        "version": "6.2(6)",
        "status": "affected"
      },
      {
        "version": "6.2(6b)",
        "status": "affected"
      },
      {
        "version": "6.2(8)",
        "status": "affected"
      },
      {
        "version": "6.2(8a)",
        "status": "affected"
      },
      {
        "version": "6.2(8b)",
        "status": "affected"
      },
      {
        "version": "6.2(10)",
        "status": "affected"
      },
      {
        "version": "6.2(12)",
        "status": "affected"
      },
      {
        "version": "6.2(18)",
        "status": "affected"
      },
      {
        "version": "6.2(16)",
        "status": "affected"
      },
      {
        "version": "6.2(14)",
        "status": "affected"
      },
      {
        "version": "6.2(6a)",
        "status": "affected"
      },
      {
        "version": "6.2(20)",
        "status": "affected"
      },
      {
        "version": "6.2(1)",
        "status": "affected"
      },
      {
        "version": "6.2(5b)",
        "status": "affected"
      },
      {
        "version": "6.2(9)",
        "status": "affected"
      },
      {
        "version": "6.2(9a)",
        "status": "affected"
      },
      {
        "version": "6.2(9b)",
        "status": "affected"
      },
      {
        "version": "6.2(11)",
        "status": "affected"
      },
      {
        "version": "6.2(13a)",
        "status": "affected"
      },
      {
        "version": "6.2(13b)",
        "status": "affected"
      },
      {
        "version": "6.2(17)",
        "status": "affected"
      },
      {
        "version": "6.2(20a)",
        "status": "affected"
      },
      {
        "version": "6.2(22)",
        "status": "affected"
      },
      {
        "version": "6.2(27)",
        "status": "affected"
      },
      {
        "version": "6.2(29)",
        "status": "affected"
      },
      {
        "version": "6.2(24)",
        "status": "affected"
      },
      {
        "version": "6.2(24a)",
        "status": "affected"
      },
      {
        "version": "6.2(33)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F1(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F2(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F2(2)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(3)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(3a)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(4)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(3c)",
        "status": "affected"
      },
      {
        "version": "7.0(3)F3(5)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(2)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(3)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(4)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(5)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(6)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(7)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(8)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(8a)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(8b)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(8z)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I4(9)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I5(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I5(2)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I6(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I6(2)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(1)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(2)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(3)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(4)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(5)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(5a)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(6)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(7)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(8)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(9)",
        "status": "affected"
      },
      {
        "version": "7.0(3)I7(10)",
        "status": "affected"
      },
      {
        "version": "7.1(0)N1(1a)",
        "status": "affected"
      },
      {
        "version": "7.1(0)N1(1b)",
        "status": "affected"
      },
      {
        "version": "7.1(0)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(1)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(2)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(3)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(3)N1(2)",
        "status": "affected"
      },
      {
        "version": "7.1(4)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(5)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.1(5)N1(1b)",
        "status": "affected"
      },
      {
        "version": "7.2(0)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.2(1)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.2(2)D1(2)",
        "status": "affected"
      },
      {
        "version": "7.2(2)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(0)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(0)DX(1)",
        "status": "affected"
      },
      {
        "version": "7.3(0)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(1)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(1)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(2)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(2)D1(2)",
        "status": "affected"
      },
      {
        "version": "7.3(2)D1(3)",
        "status": "affected"
      },
      {
        "version": "7.3(2)D1(3a)",
        "status": "affected"
      },
      {
        "version": "7.3(2)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(3)N1(1)",
        "status": "affected"
      },
      {
        "version": "8.0(1)",
        "status": "affected"
      },
      {
        "version": "8.1(1)",
        "status": "affected"
      },
      {
        "version": "8.1(2)",
        "status": "affected"
      },
      {
        "version": "8.1(2a)",
        "status": "affected"
      },
      {
        "version": "8.1(1b)",
        "status": "affected"
      },
      {
        "version": "8.2(1)",
        "status": "affected"
      },
      {
        "version": "8.2(2)",
        "status": "affected"
      },
      {
        "version": "8.2(3)",
        "status": "affected"
      },
      {
        "version": "8.2(4)",
        "status": "affected"
      },
      {
        "version": "8.2(5)",
        "status": "affected"
      },
      {
        "version": "8.2(6)",
        "status": "affected"
      },
      {
        "version": "8.2(7)",
        "status": "affected"
      },
      {
        "version": "8.2(7a)",
        "status": "affected"
      },
      {
        "version": "8.2(8)",
        "status": "affected"
      },
      {
        "version": "8.2(9)",
        "status": "affected"
      },
      {
        "version": "8.2(10)",
        "status": "affected"
      },
      {
        "version": "8.2(11)",
        "status": "affected"
      },
      {
        "version": "8.3(1)",
        "status": "affected"
      },
      {
        "version": "8.3(2)",
        "status": "affected"
      },
      {
        "version": "9.2(1)",
        "status": "affected"
      },
      {
        "version": "9.2(2)",
        "status": "affected"
      },
      {
        "version": "9.2(2t)",
        "status": "affected"
      },
      {
        "version": "9.2(3)",
        "status": "affected"
      },
      {
        "version": "9.2(4)",
        "status": "affected"
      },
      {
        "version": "9.2(2v)",
        "status": "affected"
      },
      {
        "version": "7.3(4)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(3)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(4)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(5)N1(1)",
        "status": "affected"
      },
      {
        "version": "8.4(1)",
        "status": "affected"
      },
      {
        "version": "8.4(2)",
        "status": "affected"
      },
      {
        "version": "8.4(3)",
        "status": "affected"
      },
      {
        "version": "8.4(2b)",
        "status": "affected"
      },
      {
        "version": "8.4(4)",
        "status": "affected"
      },
      {
        "version": "8.4(2c)",
        "status": "affected"
      },
      {
        "version": "8.4(4a)",
        "status": "affected"
      },
      {
        "version": "8.4(5)",
        "status": "affected"
      },
      {
        "version": "8.4(6)",
        "status": "affected"
      },
      {
        "version": "8.4(6a)",
        "status": "affected"
      },
      {
        "version": "8.4(7)",
        "status": "affected"
      },
      {
        "version": "8.4(2f)",
        "status": "affected"
      },
      {
        "version": "8.4(8)",
        "status": "affected"
      },
      {
        "version": "8.4(9)",
        "status": "affected"
      },
      {
        "version": "9.3(1)",
        "status": "affected"
      },
      {
        "version": "9.3(2)",
        "status": "affected"
      },
      {
        "version": "9.3(3)",
        "status": "affected"
      },
      {
        "version": "9.3(4)",
        "status": "affected"
      },
      {
        "version": "9.3(5)",
        "status": "affected"
      },
      {
        "version": "9.3(6)",
        "status": "affected"
      },
      {
        "version": "9.3(7)",
        "status": "affected"
      },
      {
        "version": "9.3(7a)",
        "status": "affected"
      },
      {
        "version": "9.3(8)",
        "status": "affected"
      },
      {
        "version": "9.3(9)",
        "status": "affected"
      },
      {
        "version": "9.3(10)",
        "status": "affected"
      },
      {
        "version": "9.3(11)",
        "status": "affected"
      },
      {
        "version": "9.3(2a)",
        "status": "affected"
      },
      {
        "version": "9.3(12)",
        "status": "affected"
      },
      {
        "version": "9.3(13)",
        "status": "affected"
      },
      {
        "version": "7.3(6)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(5)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(7)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(7)N1(1a)",
        "status": "affected"
      },
      {
        "version": "7.3(7)N1(1b)",
        "status": "affected"
      },
      {
        "version": "7.3(6)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(8)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(7)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(9)N1(1)",
        "status": "affected"
      },
      {
        "version": "10.1(1)",
        "status": "affected"
      },
      {
        "version": "8.5(1)",
        "status": "affected"
      },
      {
        "version": "7.3(10)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(8)D1(1)",
        "status": "affected"
      },
      {
        "version": "10.2(1)",
        "status": "affected"
      },
      {
        "version": "10.2(1q)",
        "status": "affected"
      },
      {
        "version": "10.2(2)",
        "status": "affected"
      },
      {
        "version": "10.2(3)",
        "status": "affected"
      },
      {
        "version": "10.2(3t)",
        "status": "affected"
      },
      {
        "version": "7.3(9)D1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(11)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(12)N1(1)",
        "status": "affected"
      },
      {
        "version": "10.3(1)",
        "status": "affected"
      },
      {
        "version": "10.3(3)",
        "status": "affected"
      },
      {
        "version": "10.3(99w)",
        "status": "affected"
      },
      {
        "version": "10.3(99x)",
        "status": "affected"
      },
      {
        "version": "10.3(4a)",
        "status": "affected"
      },
      {
        "version": "10.3(5)",
        "status": "affected"
      },
      {
        "version": "7.3(13)N1(1)",
        "status": "affected"
      },
      {
        "version": "7.3(14)N1(1)",
        "status": "affected"
      },
      {
        "version": "10.4(1)",
        "status": "affected"
      },
      {
        "version": "10.4(2)",
        "status": "affected"
      }
    ]
  }
]

6 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

0.023 Low

EPSS

Percentile

89.7%