Cisco Security Update – 02 July 2024

Cisco has released a security update to address a vulnerability affecting Cisco NX-OS Software.

The addressed vulnerability could allow the local attacker with administrative privileges to execute arbitrary code and gain access to the affected system by sending a specially crafted input.

Cisco NX-OS Software Command Execution Vulnerability (CVE-2024-20399):

  • CVSS: 6
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that Cisco is aware that the zero-day vulnerability “CVE-2024-20399” is being exploited in the wild and targeted by many threat actors.

Vulnerabilities

CVE-2024-20399

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Update

References